Security audit
iaiops-energy
Security checks for vulnerabilities and agentic risk
Overview
This skill is a clearly scoped, read-only energy telemetry integration, though users should treat live substation access and the external pip package as sensitive.
Install only in an authorized environment, confirm the pip package source is trusted, keep IAIOPS_MASTER_PASSWORD in a secret manager, and test against non-production or approved endpoints first because even read-only polls can affect operational links.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
