Back to skill

Security audit

Lean Startup

Security checks for vulnerabilities and agentic risk

Overview

This is a Markdown-only Lean Startup coaching skill with no hidden execution, persistence, or data access behavior.

Before installing, expect this skill to influence product-planning conversations around MVPs and startup experiments. It does not appear to run code or access data, but broad activation terms mean it may appear in some ordinary build-planning discussions where a narrower execution framework would be better.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · examples/ai-native-lean-startups-2023-2026.md (reported line 9)May include surrounding context.

md
After the November 2022 release of ChatGPT and the 2023–2024 arrival of capable foundation-model APIs (OpenAI, Anthropic, Google), a wave of small teams built products as thin layers over these models. The economics inverted the classic build cost: a two-person team could ship a working AI feature in days by calling an API, rather than spending months training a model. This made the *Build* phase almost free — and moved the real risk somewhere the Lean Startup framework anticipates but that demo culture ignores.

The recurring 2023–2026 failure pattern: a startup demos an impressive AI feature, raises on the demo, and then a subsequent model release from the underlying provider (or an open-weight model) absorbs that feature into the base capability — the "GPT-wrapper gets wrapped" problem. The dramatic public reminder came in **January 2025**, when the Chinese lab **DeepSeek** released a strong, low-cost open-weight reasoning model; the reaction rippled through markets and, on **27 January 2025**, Nvidia's share price fell sharply in a single session — a widely reported signal that the cost and moat assumptions underpinning many AI plans could shift without warning.

The Lean Startup correction: in an AI-native startup, the load-bearing assumption is almost never "can we build the feature?" (you can — cheaply). It is **"does a specific customer keep using and paying for the workflow *after* the underlying model capability becomes a commodity available to everyone?"** That is a retention-and-willingness-to-pay assumption, and it is exactly what a demo does not test.

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · references/sources.md (reported line 11)May include surrounding context.

md
After the November 2022 release of ChatGPT and the 2023–2024 arrival of capable foundation-model APIs (OpenAI, Anthropic, Google), a wave of small teams built products as thin layers over these models. The economics inverted the classic build cost: a two-person team could ship a working AI feature in days by calling an API, rather than spending months training a model. This made the *Build* phase almost free — and moved the real risk somewhere the Lean Startup framework anticipates but that demo culture ignores.

The recurring 2023–2026 failure pattern: a startup demos an impressive AI feature, raises on the demo, and then a subsequent model release from the underlying provider (or an open-weight model) absorbs that feature into the base capability — the "GPT-wrapper gets wrapped" problem. The dramatic public reminder came in **January 2025**, when the Chinese lab **DeepSeek** released a strong, low-cost open-weight reasoning model; the reaction rippled through markets and, on **27 January 2025**, Nvidia's share price fell sharply in a single session — a widely reported signal that the cost and moat assumptions underpinning many AI plans could shift without warning.

The Lean Startup correction: in an AI-native startup, the load-bearing assumption is almost never "can we build the feature?" (you can — cheaply). It is **"does a specific customer keep using and paying for the workflow *after* the underlying model capability becomes a commodity available to everyone?"** That is a retention-and-willingness-to-pay assumption, and it is exactly what a demo does not test.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The activation description includes phrases like "MVP" and "should we just build it?", which commonly appear in ordinary product or engineering conversations outside a true Lean Startup coaching need. Although some exclusions are provided, these triggers are still broad enough to risk unintended invocation in everyday planning discussions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.