Back to skill

Security audit

competitor-analysis-report-generator

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward report-generation skill with disclosed market-research data gathering and no executable code or persistence.

Install only if you want an agent to perform competitive market research and generate reports. Treat any web search or market-data API use as potentially external, and avoid including non-public strategy, customer lists, confidential pricing, or internal plans unless you explicitly intend that context to be used for research.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly references web search, API access, and distribution of generated reports but does not clearly warn users that external services may be contacted or that data may be sent outbound. In an agent environment, this can lead to unintended disclosure of user-provided business information, competitor lists, market plans, or internal strategy context to third-party services.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file lists specific trigger keywords as slash commands, but the first usage example activates the skill with the generic natural-language phrase "Generate a competitor analysis report for Tesla" instead of one of those commands. This creates ambiguity about whether invocation is restricted to explicit commands or also responds to common business-language requests, increasing the chance of unintended activation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest description says the skill supports Markdown, PDF, and PPT export formats, but the skill documentation later advertises Excel and JSON outputs as available formats. That is a semantic mismatch between the declared behavior in the manifest and the broader functionality claimed elsewhere in the skill file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The note "Use most recent data available (标注 data date)" introduces a Chinese-language requirement in the skill instructions without offering the user a language or locale choice. This can violate language/locale policy because it imposes a non-user-selected language convention in output or workflow guidance.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.