Back to skill

Security audit

Live Product Lineup

Security checks for vulnerabilities and agentic risk

Overview

This is a non-executable markdown skill for planning live-commerce product order and scripts, with some sales-pressure wording but no code, credential use, persistence, or hidden system access.

Install only if you want help planning live-commerce sessions. Operators should use truthful stock, discount, availability, and bonus claims, and should review generated scripts for platform policy compliance and consumer-protection obligations before going live.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
This is a markdown file, so vague-trigger review applies. The description explains what the skill does but gives no explicit trigger phrases, scope constraints, or negative examples clarifying when the skill should or should not activate, which can cause unintended invocation from broad product-planning requests.

Missing User Warnings

Medium
Confidence
86% confidence
Finding
This markdown file contains scripted countdown and scarcity language such as 'count down from 10,' 'When these are gone, they're gone,' and 'after that I'm pulling it' without any warning or balancing disclosure. For markdown files, SQP-2 applies when the skill description omits warnings about behaviors that could affect user data, privacy, or system integrity; here the main issue is user-impactful purchasing pressure with no cautionary framing for the operator.

Static analysis

No suspicious patterns detected.