Back to skill

Security audit

Cb Social Channel Matrix

Security checks for vulnerabilities and agentic risk

Overview

This is a descriptive marketing strategy skill with no code execution, API use, persistence, or hidden data access.

This skill appears safe to install for strategy guidance. Treat its platform recommendations, audience claims, ad-cost examples, and policy comments as planning inputs, not current facts; verify live platform availability, advertising restrictions, local laws, and market data before launching campaigns.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The skill includes a full usage scenario in Chinese and presents the expected output only in Chinese, but it does not state that the skill is China-market-specific or that Chinese output is optional. This can conflict with language/locale policy expectations because it implicitly forces a specific language without user opt-in.

Natural-Language Policy Violations

Low
Confidence
95% confidence
Finding
The manifest sets the skill language to "en", which indicates an English-only constraint. Under the policy, locale or language restrictions should either be user-selectable or clearly justified as region-specific; neither is present here.

Static analysis

No suspicious patterns detected.