Back to skill

Security audit

test

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only CMS development helper with no install scripts, executables, credential requests, or hidden privileged behavior.

Reasonable to install for WordPress or Drupal development help. Review generated CMS code before applying it to production, especially plugin/module installs, database changes, authentication flows, permissions, escaping, nonces, and deployment commands.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
This is a markdown file, so vague-trigger checks apply. The instruction "Reference this agent by name or specialty when you need its expertise" does not define concrete trigger phrases or boundaries, and "specialty" is broad enough to overlap with ordinary discussion of CMS work, increasing the chance of unintended invocation.

Static analysis

No suspicious patterns detected.