Security audit
Email Creative Builder
Security checks for vulnerabilities and agentic risk
Overview
This skill is a disclosed email-copy drafting assistant with limited, purpose-aligned local reads and no hidden execution or sending behavior.
Before installing, be aware that this skill is intended to work with marketing context such as landing pages, claims records, campaign exports, and consent/suppression information. Use it for drafting and review support, not as authorization to send email; verify claims, compliance details, and recipient consent separately.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
