Security audit
linux-riscv-contribute
Security checks for vulnerabilities and agentic risk
Overview
This skill is a disclosed, human-gated workflow for Linux RISC-V contribution work, with expected but meaningful authority over local code, GitHub issues, agents, and patch preparation.
Before installing, review the generated workflow.yaml values, especially GitHub repo, assignee, mailing lists, agent IDs, and model names. Run it in a clean branch or disposable worktree, use least-privileged GitHub credentials, and keep the human approval gates enabled before issue updates or any email sending.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
