Back to skill

Security audit

Security Intelligent Marketing

Security checks for vulnerabilities and agentic risk

Overview

This skill is a financial-marketing drafting aid with clear no-execution and no-customer-data boundaries, though users must avoid pasting real customer records into it.

Install only if you need regulated financial-marketing draft support and can review the Chinese guidance. Do not paste real customer lists, phone numbers, account balances, IDs, addresses, or other identifiable financial data; use approved internal systems for customer selection and compliance sign-off before any campaign is saved or launched.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The document is nominally bilingual, but the substantive operational guidance, examples, compliance workflows, and code comments are overwhelmingly in Chinese, while English is limited to brief summaries and trigger labels. This creates a de facto language requirement for users to work in Chinese without an explicit opt-in or documented justification for restricting the skill's primary operating language.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly claims it does not process customer lists or identifiable data, yet the included examples and code operate on per-customer records with fields like assets, age, risk preference, payroll status, phone-personalized templating, and other customer attributes. This mismatch can mislead users or downstream agents into supplying or handling regulated personal financial data in contexts that were represented as abstract or non-PII-only, increasing privacy, compliance, and data-minimization risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.