Back to skill

Security audit

Influencer Discovery

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed marketing workflow for finding and screening public influencer candidates, with limited optional persistence that requires separate authorization.

Before installing, be comfortable with a workflow that researches public creator profiles and may record public business contact paths if you explicitly authorize saving or CRM-style handoff. Use it for professional outreach only, avoid collecting private contact details, and authorize persistence only when you have a clear business need.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The template explicitly prompts users to collect and record influencer email addresses, agency/manager details, and preferred contact methods, but provides no privacy, legality, or data-handling guidance. In a discovery workflow that aggregates personal data at scale, this increases the risk of unnecessary collection, retention, sharing, or misuse of personal contact information, especially across jurisdictions with privacy requirements.

Static analysis

No suspicious patterns detected.