← Files Argovance Skill OSARCHIVED FILE
skills/secure-skill-supply-chain/references/threat-model.md
984 Bytes · Oct 5, 2026 · 18:35 UTC
# Skill threat model Inspect for: - instructions attempting to override platform rules or conceal behavior; - reading credentials, SSH keys, browser profiles, cookies, keychains, environment secrets, or unrelated files; - uploading or transmitting content to undeclared destinations; - destructive or broad filesystem commands; - shell interpolation, encoded commands, dynamic execution, download-and-run patterns; - dependency confusion, unpinned packages, mutable URLs, install hooks, and unexpected binaries; - hidden files, archive traversal, symlink escapes, and writes outside declared scope; - unauthorized email, publishing, financial, account, infrastructure, or production actions; - persistence, self-modification, silent monitoring, or privilege escalation; - misleading descriptions that do not match actual behavior. Static checks can miss contextual attacks and produce false positives. Use manual review and sandboxed testing before trusting consequential skills.
SHA-256: 10ea943bd992b65765300036c2301b37cdb3308568404b4a7b5bc16dc9158f2d