Back to skill

Security audit

session-archiver

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward session-log archiver that writes structured notes and does not include hidden execution, network access, or unrelated data collection.

Review the generated archive before keeping it long term, especially for secrets, credentials, private URLs, or sensitive project details. The skill's file access is proportionate to its purpose, but archived memory files can retain information beyond the original session.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.