Back to skill

Security audit

Content Repurposing Toolkit

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a sales page that advertises missing paid functionality and directs users to external payment channels rather than providing the promised toolkit.

Review this carefully before installing. The local skill does not include the advertised Pro files, templates, or Python scripts, and any payment or files received through Telegram, PayPal, or crypto would be outside this review. Do not execute any later-delivered scripts unless they are separately reviewed and integrity-verified.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

other

Warning
Location
SKILL.md:1
Finding

Misleading Capability Claims and External Payment Redirection

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 1-2 and 13-50
Vulnerability Type: Deceptive commercial redirection
Risk Level: Medium

The package consists solely of SKILL.md, but its metadata advertises a complete content-repurposing toolkit containing automated workflows and three Python scripts. The actual file primarily redirects users to external Telegram, PayPal, and cryptocurrency payment channels to obtain the advertised functionality.

Relevant code snippets:

markdown
description: "Turn 1 piece of content into 10+ formats for maximum distribution. Complete transformation matrix: blog to Twitter thread, LinkedIn article, newsletter, email sequence, video script, carousel, podcast notes, infographic, social snippets, and SEO blog post. Multi-platform repurposing workflow with SEO optimization including canonical URLs, structured data, and keyword mapping. Bulk processing for handling 10+ pieces simultaneously. Multi-language support (English to Vietnamese). Quality scoring rubric with 0-100 pre-publish checks. Includes 3 Python scripts for automated repurposing. For content creators, marketers, YouTubers, and podcasters who want every piece of content to work harder."
markdown
-. Pro version $4.99 → paypal.me/cofi295/4.99"Turn this blog post into a Twitter thread, LinkedIn article, and newsletter"
markdown
The Pro version (available on Telegram: @Cofi_ClawSkill_Bot) includes everything above plus:
markdown
## 🚀 Upgrade to Pro — $4.99 (Lifetime)

**What you get in Pro:**
• All templates + Python scripts + real examples (18 files)
• Lifetime access & updates — no subscription, no extra fees
• Instant delivery after payment

**[💳 Buy Pro $4.99 via PayPal →](https://paypal.me/cofi295/4.99)**

Or pay with **USDT (BEP-20)**:
`0x2927fdf1d705092cf881e1287a71ac56511b550d`

Technical Analysis

The declared package capabilities do not match the ...[truncated 2278 chars]

Remediation
View remediation

Remediation Suggestions

  1. Make the package description accurately reflect the files and functionality included in the audited distribution.
  2. Include the advertised templates, workflows, examples, and scripts locally if they are intended to be part of the skill.
  3. Clearly separate free functionality from optional paid functionality without implying that absent resources are bundled.
  4. Remove payment solicitations from operational skill instructions, or move them to clearly labeled publisher documentation that is not loaded as agent guidance.
  5. Avoid directing users to irreversible payment methods without verifiable publisher identity, refund terms, delivery terms, and support information.
  6. Distribute additional scripts through a versioned, integrity-verifiable release channel so they can be audited before execution.
  7. Provide checksums or signed releases for any externally delivered files and instruct users not to execute unaudited attachments.
  8. Correct the malformed front matter and validate SKILL.md against the expected skill manifest schema.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file describes activation through generic example phrases like turning content into other formats, but it does not define explicit trigger phrases, scope limits, or negative examples. Because these requests overlap with common everyday writing-assistance prompts, the skill could be invoked unintentionally in normal conversation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file functions primarily as an advertisement and payment funnel rather than an operational content-repurposing skill. In a skill ecosystem, this is risky because it shifts users from reviewed content to unreviewed external channels such as Telegram, PayPal, and crypto payment flows, where malicious payloads, scams, or undisclosed data handling could occur.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The metadata promises substantive automation capabilities, templates, and Python scripts, but the actual skill content only markets an external paid product and provides no in-skill implementation. This is dangerous because it misrepresents the skill’s capabilities, can mislead users into trusting or purchasing off-platform resources, and creates a delivery path to unreviewed external content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The description specifies multi-language support as 'English to Vietnamese,' which imposes a locale/language path in the skill description without stating that users can choose or opt in to that language behavior. Under the policy, language constraints should be optional or clearly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The markdown advertises a specific language conversion workflow '(EN to VN)' as a built-in feature, but does not say that the user selects this language pair or that other locales are available. This can conflict with language/locale policy requiring choice or clear justification.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

Embedding direct payment solicitation and a cryptocurrency wallet is not necessary for a content-repurposing skill and introduces financial-risk surface unrelated to the declared function. Even without code execution, this can facilitate phishing, payment fraud, or pressure users into off-platform transactions with no security assurances.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.