Back to skill

Security audit

Agent Workspace Manager

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed workspace organizer; it can guide file moves, renames, archiving, and cleanup, but I found no hidden installer, network behavior, credential handling, or deceptive instructions.

Install this only for workspaces where you want an agent to organize files. Ask for a dry-run report before allowing moves, renames, archives, merges, or removals, and review any proposed cleanup of memory, preferences, SQL, or task files before applying it.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.