Back to skill

Security audit

Cleaning Maid Service Marketing Kit

Security checks for vulnerabilities and agentic risk

Overview

This is a prompt-only marketing kit for cleaning businesses, with some compliance/privacy caveats but no hidden execution, persistence, credential access, or automatic posting behavior.

Before using the generated templates, review all outreach emails and referral language for consent, unsubscribe, physical mailing address, platform rules, and local marketing-law requirements. Do not send cold email or collect referred contacts unless you have a lawful basis and appropriate notice.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
80% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · README.md (reported line 44)May include surrounding context.

md
1. Download the skill
2. Open `prompts/01_seasonal_campaign.md`
3. Copy the prompt into Claude
4. Fill in your business details in the [BRACKETS]
5. Paste the output into your Google Ads account / Facebook Ads Manager / social media scheduler

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The referral email explicitly asks a customer to reply with a friend's contact information, which encourages collection and sharing of a third party's personal data without that person's prior consent. This creates privacy and compliance risk because the business may receive, store, and use personal information for marketing outreach without a clear lawful basis, notice, or consent workflow.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This is a real issue because the prompt explicitly requires CAN-SPAM-compliant cold email for commercial outreach, but the Airbnb/VRBO outreach section only mandates a footer for Email C and not for Email A or B. A model following this prompt may generate outreach emails that omit legally required sender identification and unsubscribe mechanisms, creating compliance and deliverability risk for users who send them as written.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The prompt instructs the model to generate all campaign assets in English and gives no option for the user to choose another language or locale. This is a natural-language policy concern because it imposes a specific language by default rather than offering opt-in or documenting a justified regional constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.