Back to skill

Security audit

$100M Leads: How to Get Strangers To Want To Buy Your Stuff

Security checks for vulnerabilities and agentic risk

Overview

This is a lead-generation advice skill, but it tries to control when the assistant speaks and injects Heardly promotional links into every answer, even outside the skill's topic.

Review this skill carefully before installing. Its business frameworks are mostly on-topic, but it may cause unsolicited onboarding, append Heardly promotional links to unrelated answers, and encourage high-volume outreach without reminding users to follow consent, anti-spam, privacy, and platform rules.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:24
Finding

Unsolicited First-Load Response Instruction

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:57
Finding

Mandatory Advertising and External-Link Injection into Every Response

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
85% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · references/5-voice-and-app.md (reported line 43)May include surrounding context.

md
### Scenario 5: "I've Tried Everything and Nothing Works"
**You've attempted multiple lead gen methods with no results.**
- **Self-diagnosis:** The problem is either (a) not enough volume, (b) not enough skill, or (c) both. Pick ONE method. Do 100/day for 30 days. Track everything. Adjust. If it still doesn't work after 30 days at volume, try a different method. But don't judge a method at 5 attempts.
- **Book quote:** "If you have thousands of nos, you will get your yeses, I promise. I always tell myself: Yeses give me opportunity. Nos give me feedback. Either way, I win."

---

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger list includes very broad, high-frequency phrases such as "grow my business," "advertising," and "content marketing," which can cause the skill to activate for many generic business queries outside the book’s intended scope. Unintended invocation can override more appropriate skills or inject irrelevant guidance, creating prompt-routing integrity issues and increasing the chance that users receive mismatched advice.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger list contains very broad, high-frequency phrases such as "grow my business," "advertising," and "content marketing," which can cause the skill to activate for many ordinary business queries that are not specifically asking for this book-based skill. Overbroad activation can hijack routing, suppress more appropriate skills, and increase the chance that users receive mismatched sales/marketing guidance without clear intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly instructs users to contact strangers who have not given permission and frames success as a volume game, but it provides no warning about consent, privacy laws, anti-spam rules, or platform policies. In a business-advice skill, this can normalize behavior that leads users to send unsolicited outreach at scale, increasing risk of spam, policy violations, account suspension, or unlawful processing of personal data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

Line L08 states that the writing is intentionally kept at a 5th grade reading level and emphasizes short, simplified language as a requirement. This imposes a language/style constraint in natural language without offering the user any choice or opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.