Back to skill

Security audit

CEO小茂 Agent

Security checks for vulnerabilities and agentic risk

Overview

The package is internally consistent with its stated purpose: a coordination-focused CEO assistant that scaffolds a workspace; it only creates local template files and does not request credentials or perform network calls.

This package appears to do exactly what it says: create a local CEO-style agent workspace with templates and docs. Before installing/running: 1) run the init script in a directory you control (it creates files using the current working directory or CEO_XIAOMAO_WORKDIR); avoid running it at system or root-level directories; 2) review the files created (SOUL.md, USER.md, MEMORY.md, AGENTS.md, IDENTITY.md and folders) to ensure they don't contain sensitive defaults; 3) if you plan to install the companion package (ceo-xiaomao) for execution capabilities, review that package separately — it may request service credentials (mail, WhatsApp, Feishu, etc.); and 4) if you need stricter autonomy controls, consider disabling autonomous invocation for the agent or reviewing agent routing rules before granting execution privileges.

Static analysis

No suspicious patterns detected.