Back to skill

Security audit

FlowSpeech Voice Script Planner

Security checks for vulnerabilities and agentic risk

Overview

The skill artifacts are coherent developer and moderation workflows with sensitive actions disclosed and mostly gated by user direction or existing platform permissions.

Install only if you are comfortable with maintainer/developer workflows that may run local CLIs, send diffs to configured review tools, interact with GitHub or Convex, and perform staff moderation through existing authenticated permissions. Review the autoreview helper settings if you do not want full-access nested review or fallback reviewers.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.