Back to skill

Security audit

Beta Launch Waitlist Generator

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only marketing prompt pack for beta launches, with no hidden execution or persistence, but users should verify social-proof claims and follow platform outreach rules.

Before installing, treat this as a copywriting template pack. Review generated testimonials, metrics, security/compliance statements, urgency claims, and Product Hunt outreach language before publishing, and only use claims you can substantiate and outreach channels where you have permission or a clear community fit.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrase "How do I get my first 100 users?" is broad and commonly overlaps with general growth, marketing, and startup-advice requests. If used for activation, the skill may trigger in contexts where the user did not ask for a beta-launch or waitlist workflow, causing inappropriate invocation and possible prompt-surface expansion into unrelated requests.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly generates launch emails and social-proof messaging using beta results, quotes, and waitlist counts, but it provides no guardrail that these claims must be truthful, current, and used with consent. That omission can facilitate deceptive marketing, fabricated testimonials, or unauthorized use of customer statements, creating legal, platform-policy, and reputational risk.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The Product Hunt section includes upvote-ask DMs, community blasts, and a war-room playbook oriented toward pushing for votes, but it does not warn against manipulative, spammy, or policy-violating outreach. In this context, the skill may normalize brigading-style behavior or unsolicited mass messaging that violates community rules and platform terms.

Vague Triggers

Low
Confidence
82% confidence
Finding
The activation description "We're launching next month and I don't have a plan" is still relatively vague and may match many generic launch-planning or project-planning requests. This can lead to accidental selection of this skill for situations outside its intended scope, reducing reliability and increasing the chance of inappropriate automated assistance.

Static analysis

No suspicious patterns detected.