Security audit
Tender Knowledge Framework
Security checks for vulnerabilities and agentic risk
Overview
No evidence of hidden, destructive, or purpose-mismatched behavior was found in the supplied scan signals or inspected artifacts.
This looks acceptable to install from the available evidence. As with any developer or integration skill, review any commands before running them, especially those that use authenticated CLIs, external services, or write access to a repository.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
