Back to skill

Security audit

solo-os

Security checks for vulnerabilities and agentic risk

Overview

This skill is a transparent decision-making framework that reads and updates project documentation only as part of a user-confirmed workflow.

Before installing, be aware that this skill may ask the agent to search and update your project decision records, plans, specs, workflow files, and indexes. That behavior is central to the framework, but you should keep the confirmation step meaningful and review any proposed document or hook changes before allowing them to land.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.