Back to skill

Security audit

信贷尽调

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Cue credit-diligence research helper that uses an external runner and Cue credits with user confirmation.

Before installing, confirm you trust the Cue runner repository because the skill can clone or update live external code and use your local Cue API key and credits. The artifact instructs the agent to ask before spending credits and to treat the research as public-data support, not a replacement for legal, underwriting, or formal diligence review.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.