Security audit
rotifer-gene
Security checks for vulnerabilities and agentic risk
Overview
This is a coherent Rotifer Gene development manual that discloses its CLI, file, and network use, with publish/login actions left under user control.
Install only if you work with Rotifer Genes. Review commands before running them, especially npx CLI execution, login, publish, arena submit --cloud, and cloud audit curl commands that use environment credentials. Keep the work scoped to the intended project directory and avoid publishing until the included audit checks pass.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
