Security audit
OwlCoda RunKit
Security checks for vulnerabilities and agentic risk
Overview
This skill coherently manages local project coordination records and verification receipts, with high-impact actions disclosed and gated by explicit authority.
Review the RunKit workflow before installing because it will let an agent create durable project coordination artifacts and, when separately authorized, run verification or deployment-related commands. Keep the `owlrunkit` dependency pinned and local, and only grant Git, deploy, credential, or destructive authority when you intend those actions.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
