Back to skill

Security audit

Ai Security Audit

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only AI endpoint security audit guide whose sensitive questions and remediation commands fit its stated purpose.

Install only if you want guidance for auditing an exposed AI endpoint. Share the minimum endpoint details needed, do not paste API keys or passwords, and review any firewall, package-upgrade, or service-install commands before running them on a production server.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger list includes broad phrases like "security audit" and "check my endpoint," which can cause accidental activation in unrelated conversations. In a security-focused skill, unintended invocation increases the chance that users disclose sensitive infrastructure details or receive high-impact operational guidance they did not explicitly request.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill requests sensitive endpoint identifiers, hosting details, and deployment metadata without a privacy notice, minimization guidance, or safer alternatives. This can lead users to reveal public IPs, provider, ASN, and security posture data that materially lowers the effort needed for targeting if logs, prompts, or transcripts are exposed.

Static analysis

No suspicious patterns detected.