Back to skill

Security audit

Cb Pricing Psychology Advisor Publish

Security checks for vulnerabilities and agentic risk

Overview

This is a descriptive pricing-advice skill with no code execution, APIs, persistence, or hidden data handling.

Use this as strategic guidance, not as legal, tax, or regulated-pricing advice. Review recommendations with qualified local professionals before changing real prices, discount claims, tax displays, or regulated-market offers.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Low
Confidence
83% confidence
Finding
The fallback prompt at line 74 ('Or just describe your pricing challenge and target market.') is very broad and can cause the skill to activate on loosely related user input. Over-broad invocation increases the chance of accidental triggering, irrelevant guidance, or the skill being pulled into contexts where its pricing advice is not appropriate, especially in a multi-skill agent environment.

Static analysis

No suspicious patterns detected.