Back to skill

Security audit

OwlCoda RunKit

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently manages local project coordination records and verification receipts, with high-impact actions disclosed and gated by explicit authority.

Review the RunKit workflow before installing because it will let an agent create durable project coordination artifacts and, when separately authorized, run verification or deployment-related commands. Keep the `owlrunkit` dependency pinned and local, and only grant Git, deploy, credential, or destructive authority when you intend those actions.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.