Back to skill

Security audit

Approval Group Directory

Security checks for vulnerabilities and agentic risk

Overview

This skill only gives a simple reviewer-group selection instruction and does not request credentials, private files, persistence, or system access.

This appears safe to install for lightweight governance routing. Users should still verify that the returned reviewer group matches their organization’s actual review policy, since the skill does not define detailed routing rules.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.