Back to skill

Security audit

Brand Voice Style Guide Generator

Security checks for vulnerabilities and agentic risk

Overview

This is a marketing copy skill that generates brand voice guides from user-provided business information, with no hidden execution, persistence, or credential use found.

Before installing, consider that you may paste private brand strategy, customer examples, or unpublished marketing copy into prompts. Use only content you are comfortable sharing with the model or provider you run it on.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Anti-Refusal Statement

High
Category
Anti-Refusal
Content
### Five Voice Pillars

1. **Straight** — We say what we mean, first sentence. No throat-clearing, no disclaimers, no "I wanted to reach out."
2. **Proven** — Every claim has a number or a name behind it. "Faster" is meaningless. "40% less admin time" is a reason to buy.
3. **Grounded** — We use job site language, not software language. RFIs, not "tickets." Punch lists, not "task tracking."
4. **Durable** — Our copy feels like it was built to last, not churned out for clicks. Dense, specific, worth reading twice.
Confidence
80% confidence
Finding
Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Static analysis

No suspicious patterns detected.