Back to skill

Security audit

sales-call-prep

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to do what it says: create sales call-prep research and a local PDF brief, without hidden persistence or exfiltration behavior.

Install only if you are comfortable with the agent doing public company research, storing call-prep payloads and PDFs under your home directory, and optionally saving your seller profile for future briefs. In locked-down environments, preinstall or approve reportlab instead of allowing ad hoc pip installs, and avoid putting confidential customer or pricing details into generated briefs unless local retention is acceptable.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This code chunk is a PDF builder/validator, not the full sales call-prep skill described. Its primary functions are: read a JSON file, validate required fields and source references, render optional sections with gap boxes, and write a PDF. The docstring explicitly says 'render a call-prep JSON payload into a formatted PDF brief' and 'No other dependencies, no network.' That means the code assumes the ten-stage content already exists. While the resulting PDF structure aligns with the described output sections, the declared purpose says the skill runs the ten-stage route on a company for call prep/account research/battle card use, which materially implies generation of the underlying research from a company input. That capability is absent here. No undeclared risky behavior is present; the mismatch is that the implementation is only a downstream formatter/validator rather than the end-to-end route executor.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 17)May include surrounding context.

md
# Call-Prep Route

The user gives you a company. You run all ten stages in order and return a PDF.
They should never have to write a research prompt.

Support files (load on demand):
- `references/prompts.md` - the ten prompts, stop-rule fallbacks, and "done" criteria. Read first.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill writes persistent files under the user's home directory and generates output artifacts without prominently disclosing that behavior in the user-facing description. Undisclosed file creation can surprise users, leak sensitive account research onto disk, and create retention/privacy issues on shared or unmanaged systems.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs the agent to install a Python package at runtime via pip, which introduces unreviewed code from an external package source into the execution environment. Even if reportlab is a common dependency, dynamic installation expands the attack surface, can bypass environment hardening, and may execute package install hooks or pull a tampered dependency.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.