← Files Argovance Skill OSARCHIVED FILE

skills/secure-skill-supply-chain/references/threat-model.md

984 Bytes · Oct 5, 2026 · 18:35 UTC

↓ Download file

# Skill threat model

Inspect for:

- instructions attempting to override platform rules or conceal behavior;
- reading credentials, SSH keys, browser profiles, cookies, keychains, environment secrets, or unrelated files;
- uploading or transmitting content to undeclared destinations;
- destructive or broad filesystem commands;
- shell interpolation, encoded commands, dynamic execution, download-and-run patterns;
- dependency confusion, unpinned packages, mutable URLs, install hooks, and unexpected binaries;
- hidden files, archive traversal, symlink escapes, and writes outside declared scope;
- unauthorized email, publishing, financial, account, infrastructure, or production actions;
- persistence, self-modification, silent monitoring, or privilege escalation;
- misleading descriptions that do not match actual behavior.

Static checks can miss contextual attacks and produce false positives. Use manual review and sandboxed testing before trusting consequential skills.

SHA-256: 10ea943bd992b65765300036c2301b37cdb3308568404b4a7b5bc16dc9158f2d