Back to skill

Security audit

Email Design

Security checks for vulnerabilities and agentic risk

Overview

This email-design skill is coherent and purpose-aligned, but it can read connected email-platform brand data and fetch brand imagery, so users should understand those data sources before use.

Install only if you are comfortable with the agent reading your connected ESP brand settings, recent templates, media assets, and named project brand files, and potentially fetching your brand website or social imagery. Review the dry-run preview carefully before approving any real send, and consider pinning or manually installing the skill rather than relying on the unpinned npx command.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README explicitly states the skill performs a silent context check that pulls brand state from a connected ESP and project brand files before asking questions. In a skill that may access external tools and local project context, undisclosed background data access can violate user expectations, expose sensitive marketing/customer metadata, and encourage overbroad collection without informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly tells the agent to silently access connected ESP account data and local project files before any user-facing notice or confirmation. Even if the data is relevant to email design, hidden access can expose brand settings, contact metadata, addresses, and internal documents without informed consent, which violates least surprise and can over-collect sensitive context.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
88% confidence
Finding

The instruction to proceed with a silent context check and to not ask the user first enables autonomous data gathering and decision-making from connected systems. In this skill context, autonomy is more dangerous because the agent may inspect account state, templates, and files, then act on inferred values that the user never reviewed, increasing privacy and integrity risks.

Content

Scanner excerpt · SKILL.md (reported line 57)May include surrounding context.

md
## Step 1 — Context check (silent)

Pull what is already known. **Do not ask the user yet.**

If Nitrosend MCP tools are available (`nitro_*`):

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs the agent to fetch content from external websites and social profiles to source imagery, but does not require clear disclosure or approval before making those network requests. This can leak user intent or brand interest to third parties, trigger unintended outbound traffic, and expand data exposure beyond the connected ESP without the user's awareness.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.