Back to skill

Security audit

法律合规

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Cue legal-research workflow that uses an external runner and API key to produce sourced legal/compliance reports after user confirmation.

Before installing, make sure you are comfortable with the Cue runner being cloned or updated in your home directory, the runner reading your Cue API key, legal queries or uploaded case details being sent to Cue, and credits being consumed only after explicit confirmation. Do not treat generated legal research as a substitute for professional legal advice.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.