Back to skill

Security audit

build-immigration-law-firm-service-comparison-landing-page

Security checks for vulnerabilities and agentic risk

Overview

This is a small instruction-only skill for drafting immigration law firm landing pages, with no code, credentials, installs, or hidden data access.

Safe to install for supervised marketing drafting. Review all output for legal accuracy, attorney advertising compliance, jurisdiction-specific ethics rules, and client confidentiality; do not paste sensitive client facts unless your workspace and model/tooling are approved for that data.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill description is truncated and overly broad, which can cause the agent to invoke this skill in situations beyond its intended scope. In a legal-adjacent context, ambiguous activation increases the chance of generating persuasive marketing or quasi-legal content for inappropriate requests, leading to misrouting, poor safeguards, and potential unauthorized legal-adjacent assistance.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The suggested prompt is generic enough that it overlaps with ordinary marketing requests, making accidental or overbroad invocation more likely. When a skill can be triggered by common phrasing, it may preempt more appropriate tools or workflows and produce legal-industry content without sufficient context, review, or domain-specific safeguards.

Static analysis

No suspicious patterns detected.