Security audit
Lot Allocation Planner
Security checks for vulnerabilities and agentic risk
Overview
This skill is a narrow lot-allocation helper that works only on inventory data the user provides and shows no hidden access, persistence, or side effects.
Installers should understand that this skill may process business inventory quantities included in the prompt, but the artifact does not request credentials, private-file access, system integration, or permission to change inventory records.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
