Back to skill

Security audit

Institutional Governance

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be a disclosed portfolio-governance workflow for approvals and audit records, with no evidence of hidden trading, destructive behavior, or data exfiltration.

Before installing, confirm the Cloudflare D1 database and approval workflow are the ones you intend to use. Do not provide broker credentials or execution permissions; this skill is designed for governance records and approved target state, not live trading.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.