Back to skill

Security audit

Client Intake Bot Pro

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed markdown-only lead intake workflow skill, with privacy and consent considerations users should handle before connecting it to CRM, email, SMS, or calendar tools.

Before using this skill with real prospects, configure consent and opt-in language, limit collected fields to what you need, review any automated messages before enabling them, and ensure CRM, email, SMS, and newsletter integrations follow applicable privacy and marketing rules.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Context Leakage

High
Category
Data Exfiltration
Content
- 3+ months → Nurture track

4. "Tell me about your business..." (Open text)
   - Capture context for personalized response

### Phase 3: Lead Scoring
Confidence
75% confidence
Finding
Code or instructions that leak agent conversation context to external services, potentially exposing sensitive user interactions.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The description says to use the skill whenever the user needs to qualify leads, set up onboarding, or filter prospects before calls, which is a wide set of common business scenarios rather than a narrowly defined trigger. It does not provide specific invocation phrases, scope limits, or exclusion examples, increasing the chance of unintended activation.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs collection of prospect information and integration with CRM, email, SMS, calendar, and newsletter systems, yet provides no privacy, consent, retention, or data-handling guidance. This can lead users to collect personal or business-sensitive data and distribute it across third-party systems without appropriate notice, opt-in, minimization, or compliance controls.

Static analysis

No suspicious patterns detected.