Security audit
Access Review Checklist
Security checks for vulnerabilities and agentic risk
Overview
This skill only formats user-supplied workspace access changes into a checklist and does not request credentials, private files, commands, network access, or persistence.
Installing this skill should be low risk for routine access-review checklist drafting. Users should still provide only the workspace membership details needed for the checklist, since the skill may receive names, roles, or external-entry information included in the request.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
