Back to skill

Security audit

PIPL Guardrail

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local personal-information detection and masking tool whose code matches its stated purpose.

Installers should understand that this is a best-effort local compliance aid, not legal advice or a complete guarantee that all personal information will be detected. In detect mode, the output can include the original input text, so use mask or block for stronger handling of sensitive content.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.