Back to skill

Security audit

launch

Security checks for vulnerabilities and agentic risk

Overview

This skill provides product launch planning guidance and does not show hidden, destructive, or disproportionate behavior.

Before installing, be aware that the skill may read local product marketing context files if they exist so it can tailor advice. Those filenames are specific and disclosed, and there is no evidence of command execution, data exfiltration, persistence, or hidden behavior.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger description is very broad and matches many common terms like 'launch,' 'announcement,' 'go-to-market,' and 'we're about to ship,' which can cause the skill to activate in situations where a more appropriate skill should handle the request. Over-broad routing is dangerous because it can misclassify user intent, pull in irrelevant instructions, and increase the chance of context confusion or unintended file access behavior such as automatically reading local marketing context files.

Static analysis

No suspicious patterns detected.