Back to skill

Security audit

Email Marketing Engine

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only email marketing playbook; its cold outreach and list-management advice is sensitive but disclosed, compliance-aware, and does not install code or take actions itself.

Install only if you want an agent to help draft and analyze email marketing materials. Review all generated cold outreach, DNS records, automation rules, and list-cleaning actions before applying them, and use the compliance checklists with your actual jurisdiction, consent records, and platform policies.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The README prominently promotes cold outreach, analytics, deliverability, and list-health functions without equally prominent warnings about consent, lawful basis, data handling, and anti-spam/privacy obligations. In an agent setting, this can normalize processing personal data or conducting outreach workflows without sufficient guardrails, increasing the risk of privacy violations, unlawful marketing, or misuse of recipient data.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README presents natural-language example requests such as "Build a welcome sequence for my SaaS product" and "Audit my email list health" without specifying whether these are the exact triggers, optional examples, or what contexts should or should not invoke the skill. Because the file provides no explicit trigger scope, exclusion conditions, or negative examples, invocation behavior is ambiguous for a manifest/markdown description.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The top-level description claims a 'complete email marketing system' covering many operational areas including cold outreach, automation, analytics, and optimization, which makes the skill likely to trigger on a wide range of generic email-related requests. In agent environments, such broad positioning can route ambiguous user intents into high-impact actions without sufficient contextual constraints or safety gating.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 431)May include surrounding context.

md
Want to stay on the list? Just click here: [re-confirm link]
      
      If not, we'll automatically remove you in 14 days.
      Either way, no spam — that's a promise.
      
  email_2:

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 734)May include surrounding context.

list: - "Verify every email address before sending (< 3% bounce)" - "Never send to catch-all domains without verification" - "Remove any email that bounces immediately" - "Respect unsubscribe within 24 hours"

text

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 1035)May include surrounding context.

md
### Email + SMS Integration
- Email for content/education, SMS for time-sensitive alerts
- Never send same message on both channels simultaneously
- SMS opt-in is separate from email — don't assume permission
- Use email for story, SMS for action trigger

### B2B vs B2C Differences

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The natural-language command list exposes very broad generation actions such as writing cold emails, generating DNS records, and creating campaigns without embedding guardrails, approval points, or compliance checks in the invocation surface. In an agent setting, this can cause over-activation or execution of high-impact marketing/outreach tasks from underspecified prompts, increasing the chance of spam, misconfiguration, or legally noncompliant messaging.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.