Back to skill

Security audit

Email Creative Builder

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed email-copy drafting assistant with limited, purpose-aligned local reads and no hidden execution or sending behavior.

Before installing, be aware that this skill is intended to work with marketing context such as landing pages, claims records, campaign exports, and consent/suppression information. Use it for drafting and review support, not as authorization to send email; verify claims, compliance details, and recipient consent separately.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.