Security audit
PIPL Guardrail
Security checks for vulnerabilities and agentic risk
Overview
This skill is a local personal-information detection and masking tool whose code matches its stated purpose.
Installers should understand that this is a best-effort local compliance aid, not legal advice or a complete guarantee that all personal information will be detected. In detect mode, the output can include the original input text, so use mask or block for stronger handling of sensitive content.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
