Back to skill

Security audit

市场营销助手(Marketing Assistant)

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a coherent marketing-assistant skill whose logging and archival behavior is disclosed as part of the workflow, with privacy considerations users should review.

Install if you are comfortable with the skill processing and archiving marketing work products. Do not submit customer lists, contracts, confidential campaign plans, credentials, or regulated personal data unless your organization has approved the storage, retention, and access controls for those archived records.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The workflow explicitly accepts user-submitted text and attachments, may process sensitive information, and then logs and archives results, but it does not state any data minimization, retention limits, access controls, or user notice/consent requirements. In a marketing assistant context, uploaded materials can easily contain customer data, campaign plans, contracts, or other confidential business information, so silent retention and broad archival increase privacy and data leakage risk.

Static analysis

No suspicious patterns detected.