Security audit
Remit
Security checks for vulnerabilities and agentic risk
Overview
The plugin is a disclosed authority-control tool that records and gates agent actions, with no evidence of hidden exfiltration, deception, or destructive behavior.
Before installing, understand that this plugin is meant to affect what your agent may do in future sessions. Use the setup wizard carefully, keep command and file grants short and scoped, and review the local dashboard or decision log if you use broad autonomy grants.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
