Back to skill

Security audit

SignalDig Growth Research

Security checks for vulnerabilities and agentic risk

Overview

This skill uses SignalDig to perform bounded social and SEO research when requested, with external API use disclosed and no local code execution or hidden persistence found.

Install this only if you are comfortable sending the topics, domains, URLs, and public social or SEO research requests you ask about to SignalDig under your API key. Review cost and data handling expectations for the SignalDig account, especially because the skill can be invoked implicitly for matching research requests.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

md
- Use `research_social_signals` for public discussions, posts, authors, native engagement, or cross-platform social evidence.
- Use `research_seo_signals` for keyword demand, intent, related queries, SERP, trends, competitors, GEO visibility, backlinks, ranked keywords, or traffic evidence.
- When one question genuinely requires both directions, submit one bounded analysis to each tool and keep the two `analysis_id` values separate.
- Ask one short clarification only when choosing Social versus SEO, the required platform set, or the SEO business scope would otherwise be unsafe. Do not ask the user about providers, workflows, bindings, page tokens, operation names, or storage.

## Common Execution Contract

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The default prompt instructs the agent to infer the needed evidence from the user's goal using the 'smallest useful' scope, but it does not define hard boundaries for when the skill should or should not activate. In combination with external research tooling, this can cause the agent to expand vague requests into autonomous third-party queries that exceed user expectations or organizational policy.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Implicit invocation is enabled without any visible trigger constraints, allowing the skill to activate automatically based on broad user intent rather than explicit user consent. Because this skill reaches an external MCP service for social and SEO research, unintended activation could cause unnecessary external data access, over-collection, or actions the user did not clearly request.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document states that geo_score "currently uses the fixed US/en comparison scope" and the example hard-codes market: "US" and language: "en". This imposes a specific locale for this operation without any user opt-in or alternative locale path, which is a natural-language policy concern under the language/locale rule.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · SKILL.md (reported line 180)May include surrounding context.

md
- Invalid business scope: explain the missing or invalid user-level field and ask only for that field.
- Deadline reached: return the current `analysis_id` and status so a later turn can resume with `get`; do not submit again.
- `partial`: use available evidence and identify the missing coverage.
- A requested evidence family with no records is a reported coverage limitation, not permission to resubmit, broaden scope, or discard successful families.
- `failed`: say SignalDig could not complete the requested research and suggest retrying later. Never reconstruct technical causes from hidden fields.

Read [references/mcp-contract.md](references/mcp-contract.md) before the first live call or when interpreting a response whose live schema differs from this Skill.

Scope Creep

Low
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · references/mcp-contract.md (reported line 228)May include surrounding context.

md
- Invalid business scope: explain the missing or invalid user-level field and ask only for that field.
- Deadline reached: return the current `analysis_id` and status so a later turn can resume with `get`; do not submit again.
- `partial`: use available evidence and identify the missing coverage.
- A requested evidence family with no records is a reported coverage limitation, not permission to resubmit, broaden scope, or discard successful families.
- `failed`: say SignalDig could not complete the requested research and suggest retrying later. Never reconstruct technical causes from hidden fields.

Read [references/mcp-contract.md](references/mcp-contract.md) before the first live call or when interpreting a response whose live schema differs from this Skill.

Static analysis

No suspicious patterns detected.