Security audit
weekly-report
Security checks for vulnerabilities and agentic risk
Overview
This skill is a report-writing helper that uses disclosed read-only or user-provided site data sources and does not include executable install code.
Before installing, confirm the missing provider-selection reference is intentional and only use already-configured read-only connectors for sites you control. Expect the skill to handle pasted exports, public crawls, and optional provider APIs such as Search Console, GA4, PageSpeed, or TrustGrowth, but not to make publishing or irreversible changes without owner review.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
