Security audit
Policy Sea
Security checks for vulnerabilities and agentic risk
Overview
This is an instruction-only Southeast Asia trade-policy helper with no code execution or system access, though users should verify policy answers against official sources.
Security risk appears low because the skill is instruction-only and asks for no permissions. Before relying on its trade, tax, certification, or customs guidance for business decisions, check official government or customs sources, especially because the artifact does not prove real-time data access and its displayed package/version metadata is inconsistent.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
