Security audit
news-collector
Security checks for vulnerabilities and agentic risk
Overview
This is an instruction-only news briefing skill that matches its stated purpose and does not include hidden code or automatic access to private data.
Safe to install as a briefing and template aid. If you later configure it to pull from private sources or push reports through email, chat, webhooks, or other services, review those separate credentials and delivery settings carefully.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
