Back to skill

Security audit

Brief Generator

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed influencer-brief drafting template with limited state reads and permission-gated saving.

Before installing, confirm you are comfortable with the skill reading existing marketing narrative and claims projections and, when you approve it, saving campaign brief files or proposing durable marketing facts. It does not show hidden execution, credential use, network exfiltration, or automatic persistence.

Vulnerability Patterns
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

Medium
Confidence
94% confidence
Finding
This markdown file includes example invocations such as "Create a Campaign Brief" and "Generate a brief for..." that are generic and overlap with ordinary user requests. The section does not define strict trigger boundaries, required context, or negative examples, which could cause unintended activation of the skill when users casually ask for a brief.

Memory Manipulation

High
Category
Memory Poisoning
Content
- Where to buy]

### Campaign Goal
[Clear statement of what this campaign aims to achieve]

### Why You
[Personalized note on why this influencer was selected - makes creators feel valued]
Confidence
24% confidence
Finding
Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Static analysis

No suspicious patterns detected.