Security audit
DeepRead BYOK
Security checks for vulnerabilities and agentic risk
Overview
This skill is a documentation-only guide for setting up DeepRead BYOK and clearly discloses that users provide API keys to DeepRead through its dashboard.
Before installing, confirm you trust DeepRead to receive and store your provider API key. Use scoped or limited keys where possible, monitor provider billing, and avoid pasting production keys into chats, logs, or committed files.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
