Back to skill

Security audit

MeetMatch Sales Coach

Security checks for vulnerabilities and agentic risk

Overview

This sales-coaching skill appears purpose-aligned, but it should be reviewed because it can automatically email sensitive employee and prospect performance briefings and use persistent coaching memory without clear consent, retention, or access controls.

Review this skill with sales, HR, legal, and security stakeholders before installation. Confirm who can access each rep's memory and performance data, who receives email briefings, whether reps and prospects have appropriate notice or consent, how long transcript-derived observations are retained, and whether automatic delivery and broad keyword triggers can be narrowed or disabled.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README prominently describes persistent rep tracking, cross-call memory, and ML-based meeting analysis, but provides no privacy, consent, retention, or data-use disclosure. Because this skill appears to process employee behavioral patterns and meeting risk signals, missing user-facing warnings can lead to covert collection or misuse of sensitive workplace and personal performance data.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README advertises invocation phrases like "how's my day" and "brief me on my 2pm," which are broad conversational inputs without clear activation boundaries. In an agent environment, this can cause unintended skill triggering or context confusion, especially because the skill accesses persistent coaching memory and ML-derived sales data.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

The skill describes building persistent rep memory across weeks and months from call analyses, performance trends, and coaching observations. Persistent session memory involving employee behavioral and performance data increases the risk of over-collection, unintended profiling, stale or incorrect inferences, and unauthorized access to longitudinal sensitive records if retention and access boundaries are not clearly defined.

Content

Scanner excerpt · SKILL.md (reported line 18)May include surrounding context.

md
# MeetMatch Sales Coach

Your OpenClaw agent knows how to write emails and search the web. This skill teaches it how to actually sell.

MeetMatch Sales Coach connects your agent to real sales outcome data: which reps close which types of deals, who's at risk of a no-show, what coaching patterns emerge across hundreds of calls. Your agent doesn't just read a CRM. It taps into a prediction engine trained on your team's historical close data, then turns that into personalized coaching for every rep, every morning.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly describes generating personalized morning briefings and states they are sent by email, while also processing sensitive rep performance metrics, meeting context, risk scores, and transcript-derived coaching memory. Failing to clearly warn users about this data processing and outbound delivery can lead to privacy, confidentiality, and compliance risks, especially if briefings are sent to unintended recipients or contain sensitive employee performance information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest describes scheduled email briefings containing rep performance, meeting details, prospect attributes, and persistent coaching memory, but provides no user-facing notice, consent flow, or data-handling disclosure. This creates a privacy and compliance risk because sensitive employee and prospect data may be transmitted automatically over email or surfaced by the agent without users understanding what is collected, retained, or shared.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The keyword triggers include broad, natural phrases like 'how's my day', 'what should I focus on', and 'brief me' that can easily match ordinary conversation outside a deliberate invocation context. In this skill, accidental activation is more dangerous because the assistant is instructed to fetch personalized schedule, performance, and rep-memory data from a backend, which could expose sensitive sales and employee information to the wrong context or user session.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.