Security audit
locational-marginal-prices
Security checks for vulnerabilities and agentic risk
Overview
The available scan context does not show malicious or review-worthy behavior, but the target artifact files were not present for full independent inspection.
Treat this as a clean but low-confidence pass because the available telemetry is clean while the actual artifact text was not available in the workspace. Before installing, review the skill's SKILL.md and any scripts for the permissions, data flows, and commands it asks an agent to use.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
