Back to skill

Security audit

Bathroom Remodeling Marketing Kit

Security checks for vulnerabilities and agentic risk

Overview

This is a marketing-prompt kit with no executable behavior, but some review-request templates contradict its own compliance claims and should be edited before use.

Installers should treat this as a prompt/template library, not legal advice. Before using outputs publicly, remove satisfaction-gated review wording, adapt Clark County/Nevada references to the correct jurisdiction, verify all license/permit/credential claims, and avoid unnecessary customer personal details.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (11)

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
The skill states that review requests must be unconditional, but the templates use satisfaction-conditioned language such as asking for a review only if the customer is happy or if the business earned it. That creates review gating risk and can lead users to generate FTC-noncompliant outreach despite the prompt's stated compliance posture, which makes the contradiction especially dangerous.

Intent-Code Divergence

Medium
Confidence
98% confidence
Finding
The card template explicitly asks for a review only 'if you're happy,' which contradicts the earlier FTC-ground-rule language prohibiting positive-sentiment gating. Because this skill is marketed as compliant, users may rely on it without spotting the inconsistency and deploy legally risky review solicitation language.

Intent-Code Divergence

Medium
Confidence
98% confidence
Finding
The verbal walkthrough script conditions the review request on the client being happy, which is inconsistent with the prompt's own rule that requests must be unconditional. In a script intended for frontline staff, this increases the chance that noncompliant language is used in real customer interactions at scale.

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
This aging-in-place verbal script also ties the review ask to customer satisfaction, directly undermining the no-gating rule stated elsewhere in the skill. Since the skill frames itself as compliance-aware, the mismatch may create misplaced trust and downstream regulatory exposure.

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
The commercial verbal script asks for a review only if the client is satisfied, again conflicting with the stated compliance requirement against positive-sentiment gating. This is a real compliance flaw because the skill operationalizes noncompliant wording in a reusable script.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The response templates state that permits are handled through Clark County, which imposes a specific local jurisdiction in natural-language content. The file does not clearly frame this as a locale-specific skill or provide user choice, so users outside that region could be forced into inaccurate localized output.

Vague Triggers

Medium
Confidence
85% confidence
Finding
As a markdown file, this content falls under the vague-trigger review scope. The 'How to Use' section tells the user to fill in fields and run the prompt, but it does not define when this skill should or should not be used, nor does it provide negative examples or a narrow invocation context, which can lead to unintended use in adjacent marketing scenarios.

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
The prompt's compliance gates prohibit unsupported warranty-style claims such as "lifetime guarantee" (L022, L414), but the description at L110 says the waterproofing system is "built to last." That wording materially undercuts the stated compliance intent by implying an unbounded durability claim while the surrounding guidance says such claims must be tightly qualified.

Scope Creep

Low
Category
Excessive Agency
Content
## The Problem with Generic AI for Bathroom Remodeling
Every AI tool and copywriter produces bathroom remodeling copy that contains multiple federal and state violations:
- "ADA compliant bathroom renovation" — ADA Title III applies to commercial facilities only; residential is voluntary Fair Housing Act
- "We handle everything in-house — plumbing, electrical, tile, all trades" — NRS 624.730 criminal offense without licensed sub disclosure
- "No permit needed for this update" — Clark County requires permits for all bathroom remodels; no-permit claims stop home sales at closing
- "EPA-certified lead-safe removal included" — EPA RRP Firm Certification + Certified Renovator required for pre-1978 homes; omitting it = $37,500/day penalty
- "We also handle any mold we find" — mold remediation requires IICRC S520 scope separation and separate licensure; scope-creep claim voids insurance
Confidence
70% confidence
Finding
Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Scope Creep

Low
Category
Excessive Agency
Content
- "We handle everything in-house — plumbing, electrical, tile, all trades" — NRS 624.730 criminal offense without licensed sub disclosure
- "No permit needed for this update" — Clark County requires permits for all bathroom remodels; no-permit claims stop home sales at closing
- "EPA-certified lead-safe removal included" — EPA RRP Firm Certification + Certified Renovator required for pre-1978 homes; omitting it = $37,500/day penalty
- "We also handle any mold we find" — mold remediation requires IICRC S520 scope separation and separate licensure; scope-creep claim voids insurance
- "Remove any wall to open your bathroom" — load-bearing wall removal requires PE stamp (NRS 625); "any wall" = engineering scope misrepresentation
- "Lifetime waterproofing guarantee" — Magnuson-Moss §104 requires written warranty terms; scope limits; "guarantee" without conditions = FTC unfounded claim
Confidence
65% confidence
Finding
Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Missing User Warnings

Low
Confidence
81% confidence
Finding
The template explicitly references a client's property sale and property address in outreach content, which can affect user privacy if used carelessly. While the file is compliance-focused, it does not warn users to avoid including sensitive personal details or to verify consent before referencing transaction-specific information in review requests.

Static analysis

No suspicious patterns detected.