Back to skill

Security audit

Prompt Switchboard Compare Workflows

Security checks for vulnerabilities and agentic risk

Overview

This is a clear setup guide for a local browser comparison tool, with the main cautions being its external GitHub/npm install and use of already signed-in AI chat tabs.

Before installing, review the referenced GitHub repository and npm dependencies, use only AI chat accounts and browser tabs you intend the tool to operate, and avoid sensitive prompts unless you are comfortable with those providers and any local compare history the sidecar may keep.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.