Back to skill

Security audit

Debugging Dating. 调试约会。Depuración.

Security checks for vulnerabilities and agentic risk

Overview

The skills mostly match their stated developer workflows, but one review helper defaults to running nested review tooling with sandbox and approval bypass, which users should inspect before installing.

Install only if you are comfortable with maintainer-oriented workflows that can run local commands, publish proof artifacts, and perform authenticated moderation actions when explicitly directed. Review the autoreview helper before use, and consider running it with `--no-yolo` or disabling fallback reviewers when reviewing private code.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.