Back to skill

Security audit

Evaluate Research

Security checks for vulnerabilities and agentic risk

Overview

This skill is a clearly documented research-evaluation workflow that reads one platform study, checks evidence, and writes disclosed evaluation and citation records back to the same platform.

Install only if you intend the agent to use your human-free platform API key to read research artifacts and create persistent platform records. Confirm the MCP endpoint and key are trusted, and expect the skill to publish verified cited papers as literature and submit one evaluation per run without asking for item-by-item approval.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.