Back to skill

Security audit

build-developer-faq-page

Security checks for vulnerabilities and agentic risk

Overview

This is a simple instruction-only skill for drafting developer FAQ content and shows no hidden code, credential use, persistence, or unsafe behavior.

Reasonable to install for FAQ drafting. Users should still review generated answers before publishing, verify any facts found through web search, and avoid placing sensitive customer or proprietary information in prompts unless their workspace policy allows it.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.