Back to skill

Security audit

matrixbnuhs

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only skill for cloning and running a React/TypeScript education collaboration project, with no bundled executable code or hidden behavior found.

Install only if you intend to work with the Matrix-BNUHS GitHub project. Before running the setup commands, inspect the referenced repository, prefer a pinned commit or release, review package.json for install scripts, and run npm or deployment commands in a sandbox if you need higher assurance.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description contains very broad activation conditions such as building knowledge systems, educational apps, matrix organization, collaboration editing, and deploying React frontends. This can cause the skill to be invoked for many generic software requests outside its narrowly intended scope, increasing the chance of unintended execution, overreach, or unsafe tool use in contexts where the skill is not the best match.

Static analysis

No suspicious patterns detected.