Back to skill

Security audit

Email Deliverability

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent email-deliverability audit guide with expected handling of email marketing data, but users should be careful with customer-list exports and DNS/list changes.

Before using this skill on real customer data, confirm you are authorized to export subscriber lists, share only the minimum fields needed with any verification vendor, review privacy and data-processing terms, and get approval/backups before DNS changes or bulk suppressions/removals.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 25)May include surrounding context.

md
| **Authentication (SPF/DKIM/DMARC)** | All three configured with DMARC at p=reject and aligned | SPF + DKIM in place, DMARC at p=none or p=quarantine | Missing one or more protocol, no DMARC, or misaligned records |
| **Bounce Rate** | <1% hard bounces per campaign | 1-2% hard bounces, soft bounces under 5% | >2% hard bounces or >5% soft bounces per campaign |
| **Spam Complaint Rate** | <0.05% (below 1 per 2,000 emails) | 0.05-0.08% with downward trend | >0.08% or rising trend (Google threshold is 0.10%) |
| **List Hygiene** | Verified within 90 days, engaged segments defined, sunset policy active | Verified within 6 months, basic segmentation in place | No verification in 6+ months, no segmentation, no sunset policy |
| **Sending Infrastructure** | Dedicated IP with warm-up complete, consistent volume, subdomain isolation | Shared IP with reputable ESP, moderate volume consistency | Unknown IP reputation, erratic volume, no subdomain separation |
| **Content Quality** | Personalized, mobile-optimized, <0.1% spam trigger density, clear unsubscribe | Template-based with some personalization, visible unsubscribe | Heavy image-to-text ratio, spam trigger words, hidden unsubscribe |
| **Engagement Metrics** | >20% open rate, >2.5% CTR, <0.3% unsubscribe rate | 15-20% open rate, 1.5-2.5% CTR, 0.3-0.5% unsubscribe | <15% open rate, <1.5% CTR, >0.5% unsubscribe rate |

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly instructs users to export subscriber lists with engagement metadata and submit addresses to third-party verification services, but it provides no privacy, consent, minimization, or vendor-risk guidance. That can expose personal data and behavioral data to external processors in ways that violate internal policy, contracts, or privacy laws, especially in ecommerce contexts where subscriber data is customer data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.