Back to skill

Security audit

plan-cpa-tax-advisory-firm-local-seo-faq-cluster

Security checks for vulnerabilities and agentic risk

Overview

This is an instruction-only SEO drafting skill for CPA FAQ content, with no code, credential access, persistence, or hidden system behavior.

Use this as a marketing draft assistant, not as tax or legal advice. Avoid providing client PII or confidential tax details, verify any tax-related claims with a qualified reviewer, and require human approval before publishing generated FAQ content.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
83% confidence
Finding
The skill’s usage description and workflow are broad enough that an agent could invoke it in situations outside the intended local SEO drafting task, especially because the trigger phrasing is generic and the deliverable is not tightly bounded. This can lead to unintended automation, irrelevant web research, or publication of low-quality finance-adjacent content without sufficient human review, though it does not directly enable code execution or privilege escalation.

Static analysis

No suspicious patterns detected.