Back to skill

Security audit

Marketing Brand Playbook

Security checks for vulnerabilities and agentic risk

Overview

The skill content is a coherent marketing playbook, but its documented install and scan commands rely on mutable unpinned remote execution and a global noninteractive install.

Review the install path before using this skill: pin the installer and scanner versions, install from a reviewed commit or signed release, avoid `--yes` and `--global` unless you deliberately want persistent global availability, and run any package-runner commands in a least-privileged or disposable environment.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Warning
Location
README.md:18
Finding

Unpinned Package Execution and Mutable Global Skill Installation

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
README.md:24
Finding

Execution of an Unpinned Latest Security Scanner Package

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill explicitly says to trigger on ANY marketing, branding, growth, or go-to-market topic and even to use the skill when in doubt. That creates excessive scope and routing collisions, causing the agent to invoke this skill for routine or loosely related conversations where a narrower or more appropriate skill should be selected, which can degrade safety, relevance, and system behavior.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The README instructs users to run npx skills without pinning a specific package version. Because npx resolves and executes the latest matching package by default, a compromised or malicious upstream release could be executed on the user's system during installation. In skill-installation context this is more dangerous because users are likely to copy-paste the command directly and grant it broad trust.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The security scan command uses uvx snyk-agent-scan@latest, which explicitly pulls and executes the latest version at runtime. This creates a supply-chain risk: if the package or a newly published version is compromised, users invoking the scan command may run unreviewed code. The skill context increases risk slightly because the command is presented as a security verification step, which may cause users to trust and execute it without additional scrutiny.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.