Security audit
Approval Group Directory
Security checks for vulnerabilities and agentic risk
Overview
This skill only gives a simple reviewer-group selection instruction and does not request credentials, private files, persistence, or system access.
This appears safe to install for lightweight governance routing. Users should still verify that the returned reviewer group matches their organization’s actual review policy, since the skill does not define detailed routing rules.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
