Security audit
资本运作
Security checks for vulnerabilities and agentic risk
Overview
This skill is a disclosed Cue research workflow for public capital-markets research, with expected network use, runner setup, API-key use, and credit consumption called out.
Before installing, be aware that first use may clone or update the Cue runner from GitHub or Gitee, and running research uses your Cue account key and consumes Cue credits after confirmation. Review the external runner source if that level of local code execution matters to you.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
