Back to skill

Security audit

Lot Allocation Planner

Security checks for vulnerabilities and agentic risk

Overview

This skill is a narrow lot-allocation helper that works only on inventory data the user provides and shows no hidden access, persistence, or side effects.

Installers should understand that this skill may process business inventory quantities included in the prompt, but the artifact does not request credentials, private-file access, system integration, or permission to change inventory records.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.