Security audit
私募尽调
Security checks for vulnerabilities and agentic risk
Overview
This skill is a disclosed Cue research workflow for private-fund due diligence, with expected network/API use and credit consumption after user confirmation.
Before installing, be aware that this skill may clone or update an external Cue runner, use your local Cue API key, contact Cue services, and consume account credits only after explicit confirmation. Review the Cue runner source and account settings if those costs or data flows matter for your environment.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
