Back to skill

Security audit

YouTube Script Generator

Security checks for vulnerabilities and agentic risk

Overview

The skill artifacts are coherent maintainer and Convex workflow guidance, with sensitive actions disclosed and generally gated by user confirmation or existing CLI auth.

Install only if you want repo-maintainer and Convex automation guidance. Before using moderation, PR publishing, deployment, auth setup, or autoreview helper flows, confirm the target, account, and destination service because these workflows can change public project state or send diffs/configuration context to external CLIs or provider APIs.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.