Back to skill

Security audit

Marketing Skills

Security checks for vulnerabilities and agentic risk

Overview

This is a Markdown-only marketing playbook, but some modules claim direct ad/social account access and include broad scraping or data-collection guidance without strong approval boundaries.

Install only if you want marketing advisory content, and keep connected ad accounts, social schedulers, customer-list uploads, analytics identifiers, and scraping tools behind explicit user approval. Require preview of exact posts, accounts, times, budgets, audiences, and data sources before any action, and review privacy law, consent, and platform terms before using tracking, retargeting, lead capture, or scraping guidance.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Output HandlingUnvalidated Output Injection, Cross-Context Output, Unbounded Output
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (26)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 76)May include surrounding context.

md
- `references/marketing-ideas/SKILL.md`
- `references/marketing-psychology/SKILL.md`

## Output rules

- Prefer 80/20: biggest levers first.
- Never invent metrics or keyword volumes. If missing, label assumptions.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · references/paywall-upgrade-cro/SKILL.md (reported line 542)May include surrounding context.

md
- Cool-down period after dismiss (hours vs. days)
- Escalating urgency over time vs. consistent messaging
- Once per feature vs. consolidated prompts
- Re-show rules after major engagement

**Dismiss Behavior**
- "Maybe later" vs. "No thanks" vs. "Remind me tomorrow"

Unvalidated Output Injection

High
Category
Output Handling
Confidence
65% confidence
Finding

Model output is used without validation or sanitization. Unvalidated output injected into downstream contexts (SQL, shell, HTML) enables injection attacks and arbitrary code execution.

Content

Scanner excerpt · references/schema-markup/SKILL.md (reported line 542)May include surrounding context.

md
<Head>
        <script
          type="application/ld+json"
          dangerouslySetInnerHTML={{ __html: JSON.stringify(schema) }}
        />
      </Head>
      {/* Page content */}

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest description contains broad activation phrases such as 'test this change' and 'hypothesis' that can match many ordinary product, engineering, or brainstorming requests unrelated to formal experimentation. This can cause the skill to trigger out of context, leading to unintended routing and inappropriate guidance, though the content itself is not directly harmful.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly recommends tracking identifiers such as user_id and account_id while only later mentioning privacy considerations, without a prominent user-facing warning at the point of collection. In an analytics implementation skill, this can normalize privacy-invasive tracking or lead users to deploy identification without proper consent, notice, or minimization controls.

Content

No source excerpt is available for this finding.

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
60% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · references/analytics-tracking/SKILL.md (reported line 405)May include surrounding context.

md
**GA4 DebugView**
- Real-time event monitoring
- Enable with ?debug_mode=true
- Or via Chrome extension

**GTM Preview Mode**

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger description is broad enough to match generic comparison-related requests such as 'vs page' or 'competitor comparison,' which can cause the skill to activate outside its intended niche. Unintended invocation can steer the agent into specialized SEO/sales behavior when the user wanted a neutral comparison, increasing the risk of irrelevant, biased, or policy-inappropriate outputs.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description uses broad trigger phrases such as 'edit this copy,' 'review my copy,' and 'make this better,' which can match a wide range of ordinary user requests. In an agentic routing system, overly broad activation criteria can cause this skill to be selected when a more appropriate or safer specialized skill should handle the task, leading to misrouting and reduced control over behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill description includes broad trigger phrases such as 'write copy for,' 'improve this copy,' and 'headline help,' which can match many ordinary writing requests and cause this skill to be selected when a more specialized or safer skill would be more appropriate. Over-broad routing increases the chance of misclassification, unexpected behavior, and instruction collisions across skills, especially in systems that auto-select skills based on natural language cues.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/form-cro/SKILL.md (reported line 65)May include surrounding context.

md
## Field-by-Field Optimization

### Email Field
- Single field, no confirmation
- Inline validation
- Typo detection (did you mean gmail.com?)
- Proper mobile keyboard

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases are broad and include generic terms like "calculator," "generator," and "interactive tool," which can cause the skill to activate in contexts outside its intended scope. Misrouting can lead the agent to provide marketing-oriented guidance when the user intended something else, increasing the chance of irrelevant, misleading, or privacy-impacting follow-on behavior such as unsolicited lead-capture recommendations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill gives detailed advice on collecting emails, gating results, saving or sharing outputs, and sharing anonymized results, but it does not require any user-facing privacy notice, consent language, retention limits, or data-handling safeguards. This creates a realistic risk that downstream implementations will collect personal or behavioral data without adequate transparency or compliance controls, exposing users to privacy harm and operators to regulatory and trust risks.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill description includes many broad trigger phrases such as 'launch,' 'announcement,' 'product update,' and 'go-to-market,' which are common in ordinary conversation and can cause overbroad invocation. This can lead to the skill activating in contexts where the user did not intend launch-planning behavior, increasing the chance of irrelevant guidance, context hijacking, or unintended routing to marketing-specific instructions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill description contains broad trigger phrases such as 'marketing ideas,' 'how to market,' and 'ideas to grow,' which can match many ordinary user requests and cause the skill to activate outside narrowly intended contexts. Over-broad routing is risky because it can override more specialized or safer skills, leading to irrelevant or lower-quality guidance and expanding exposure to any risky tactics contained in the skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The guidance recommends tactics like pixel sharing, retargeting, click-to-messenger ads, affiliate discovery, competitor targeting, and data-driven audience tactics without any warnings about consent, privacy law, platform terms, or data-sharing restrictions. In a marketing skill, this omission is more dangerous because users may operationalize these tactics directly and infer they are endorsed, creating legal, compliance, and trust risks.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description contains broad trigger terms such as 'psychology,' 'decision-making,' and 'consumer behavior,' which can cause the skill to activate in many unrelated contexts. Over-broad activation increases the chance that persuasive-marketing guidance is injected when a user is asking about sensitive psychological, behavioral, or decision topics outside marketing, leading to scope confusion and potentially unsafe assistance.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The activation description is broad enough to match many generic requests about improving a page, which can cause the skill to trigger when a more specific skill would be safer or more appropriate. Over-broad routing can lead to mis-scoped guidance, reduced reliability, and accidental handling of adjacent tasks such as signup flows or forms despite the text attempting to defer those cases.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description contains many broad trigger phrases such as 'ad copy,' 'ad campaign,' and 'audience targeting,' which can match a wide range of normal marketing conversations and cause the skill to activate when a more specific skill would be more appropriate. Overbroad activation increases the chance of unintended access to ad-platform-related guidance or workflows and can misroute user requests, especially because the skill claims direct access to ad platform accounts.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill advertises very broad trigger phrases such as 'upsell,' 'feature gate,' 'convert free to paid,' and 'in-app pricing,' which can cause over-activation on general monetization conversations that are not specifically about paywall design. Over-broad routing can expose users to manipulative conversion guidance in contexts where they did not request it, and it increases the chance the wrong skill is invoked.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest description says to use the skill when the user wants to create or optimize 'banners' or mentions 'overlay,' which are generic terms that can arise in many unrelated UI or design conversations. Although some examples are specific, the activation guidance does not clearly constrain when these terms should and should not invoke this popup-focused skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The activation description contains many broad trigger phrases such as generic SEO-related terms, page types, and keyword patterns, which can cause the skill to be invoked in situations where the user did not specifically request programmatic SEO guidance. Over-broad activation increases the chance of inappropriate routing, irrelevant advice, and prompt-surface expansion to a skill that may steer the conversation away from the user’s actual intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The activation description includes very broad triggers such as 'audit,' 'review,' and 'diagnose SEO issues,' which can overlap with many general website, marketing, analytics, or content requests. This can cause the skill to activate in situations outside its intended scope, leading to incorrect tool routing, irrelevant guidance, or the skill preempting more appropriate specialized skills.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger description is very broad, including generic phrases like 'social media,' 'engagement,' and 'viral content,' which can cause the skill to activate during ordinary conversation outside the user's intent. Overbroad invocation increases the chance that high-impact capabilities in the skill, such as scheduling or publishing-oriented assistance, are surfaced inappropriately.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill states it has direct access to a scheduling platform that publishes to major social networks, but it provides no warning, confirmation flow, or approval boundary for actions affecting public accounts. In context, this is more dangerous because the rest of the skill encourages planning and scheduling workflows, making accidental or unauthorized posting a realistic risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly recommends collecting 500-1000+ posts at scale using scraping and automation tools such as Apify and Phantom Buster. That expands the skill from benign content assistance into operational guidance for mass data extraction, which can violate platform terms, enable unauthorized collection of third-party content/metadata, and create compliance and abuse risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.