Back to skill

Security audit

Review Request Optimizer

Security checks for vulnerabilities and agentic risk

Overview

This is a text-only ecommerce review strategy skill with disclosed, purpose-aligned guidance and no code, credentials, persistence, or hidden data flows.

Before installing, treat this as business-marketing guidance, not legal advice. If you use its templates, adjust any wording that asks unhappy buyers to contact support 'first' so every customer still has an equal, direct path to leave a review, and confirm the final program against Amazon, Shopify, eBay, Etsy, SMS, and local advertising rules.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
85% confidence
Finding
The workflow instructs authors to add a 'negative-feedback safety route' inviting dissatisfied buyers to contact support before reviewing, and frames this as acceptable. Even though the text says 'This is not gating,' the natural-language guidance encourages steering unhappy buyers away from the review flow, which is a semantic policy concern in the skill's instructions.

Static analysis

No suspicious patterns detected.