Back to skill

Security audit

content-writing-thought-leadership

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only content-writing guide with no hidden execution, credential access, or automatic publishing behavior.

Install this if you want structured B2B content-writing guidance. Before using its recommendations, confirm the target industry, role, company approval requirements, audience geography, and legal/compliance review needs, especially for regulated sectors like fintech.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · README.md (reported line 414)May include surrounding context.

md
ly blog, 1× monthly deep-dive
- Topic progression: Build on each piece
- Engagement tactics: How to spark conversations
- Measurement: What to track (followers, engagement, inbound leads)

---

## 🔧 Integration & Workflow

### Works Best With:

**Content Management:**
- Notion (organize content calendar)
- Airtable (track content ideas)
- Google Docs (drafting and collaboration)

**Scheduling Tools:**
- Buffer, Hootsuite (social media)
- Medium (publishing)
- Substack (newsletters)

**Research Tools:**
- Google Trends (topic validation)
- AnswerThePublic (question research)
- BuzzSumo (competitor content analysis)

### Typical Workflow:

1. **Ideation** (Monday, 30 minutes)
   - Use skill to generate 20 topic ideas
   - Filter to 7 best ideas (1 per day)
   - Add to content calendar

2. **Batching** (Wednesday, 2 hours)
   - Write first drafts (all 7 pieces)
   - Use templates from skill
   - Don't edit, just write

3. **Editing** (Friday, 1 hour)
   - Edit Monday-Wednesday content

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The markdown states that geography determines writing style and then assigns distinct styles such as 'US direct' versus 'India relationship-focused.' This is a natural-language locale policy issue because it pushes locale-specific defaults rather than offering the user a choice or framing them as optional adaptations.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 1989)May include surrounding context.

text
ADVANTAGES:
✅ No approval needed (publish freely)
✅ Personal voice = authentic
✅ Can be contrarian (if industry allows)
✅ Can share company metrics

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

These sections prescribe country-specific content style, examples, timing, and CTAs for India and the US as default guidance. Because the skill does not explicitly obtain user preference before imposing these locale norms, it risks violating language/locale choice expectations.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 2191)May include surrounding context.

→ Fintech → Section C (ultra-conservative mandatory)

text

### **Mistake 2: "No Approval Process (When You Need One)"**

SCENARIO: Employee Publishes Without Manager Knowing

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 2631)May include surrounding context.

→ Fintech → Section C (ultra-conservative mandatory)

text

### **Mistake 2: "No Approval Process (When You Need One)"**

SCENARIO: Employee Publishes Without Manager Knowing

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README states that the frameworks are optimized for English content and may not adapt well to non-English norms. Because this is a natural-language capability statement in a markdown file, it can create an implicit language constraint without presenting users an explicit language or locale choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.