Back to skill

Security audit

智能数据研究工作站

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed data research bundle for search, crawling, local archiving, and SQL-style analysis, with no bundled executable code or hidden behavior found.

Install only if you want an agent to perform web searches, crawl public pages, write local archives, and possibly run scheduled sync jobs. Provide API keys through environment variables, keep crawl scope limited to approved public sources, and review any scheduled sync or notification configuration before enabling it.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.