Back to skill

Security audit

customer-acquisition-automation

Security checks for vulnerabilities and agentic risk

Overview

This skill gathers public marketing leads and drafts outreach, with clear limits and a human approval step before anything is posted.

Install this only if you want an agent to research public posts and prepare marketing drafts. Invoke it with a clear acquisition request, review the generated lead pool and drafts carefully, and do not provide API credentials unless you are ready to control any later publishing step yourself.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrases are broad enough that normal user requests like 'draft outreach' or 'run acquisition' could invoke this skill unintentionally, causing autonomous collection of leads and generation of marketing content without the user clearly opting into this workflow. In this context, accidental activation is meaningful because the skill performs external-content gathering and creates persuasive outreach drafts, which can lead to unwanted actions, policy issues, or user surprise even though publishing is human-gated.

Static analysis

No suspicious patterns detected.