Back to skill

Security audit

attacker

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed red-team review skill that asks agents to critique targets and record findings, without evidence of hidden data access, destructive behavior, or exfiltration.

Install only if you want an aggressive critique workflow. Expect it to use web search, run reproduction commands when you allow that, spawn fresh review contexts if your host supports them, and write local findings/ledger records in the target project. Review commands before execution on sensitive repositories.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrase and positioning are broad enough that the skill could activate for ordinary critique, review, or analysis requests, causing unintended invocation on arbitrary user content. In agent ecosystems, overbroad routing can expose sensitive inputs to a more aggressive skill than intended, expand attack surface, and bypass user expectations about when adversarial analysis should occur.

Static analysis

No suspicious patterns detected.