Back to skill

Security audit

Overllm

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed local code-linting helper for finding unnecessary LLM API calls, with no evidence of hidden data collection or unsafe behavior.

Install only if you are comfortable allowing the agent to install and run the external overllm package. Normal scans should be read-only; review before using --fix or --unsafe-fixes because those modes can edit files.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.