Back to skill

Security audit

Campaign Planner

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed influencer campaign planning skill that saves a scoped plan and summary facts to memory, with no hidden execution or data export behavior found.

Installers should be comfortable with campaign details such as budget, goals, dates, and KPI targets being saved into the local memory paths named by the skill. Review or disable memory behavior if those campaign details are sensitive.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
77% confidence
Finding
This markdown skill states that it writes a campaign plan document to a memory path and promotes durable facts to a hot cache. Although the behavior is documented, there is no explicit warning to the user that invoking the skill will persist data to memory files, which could affect user data or privacy.

Static analysis

No suspicious patterns detected.