Back to skill

Security audit

RFM Segmenter

Security checks for vulnerabilities and agentic risk

Overview

This is a marketing analysis guide that uses customer order data for RFM segmentation, with privacy and outreach-compliance caveats but no hidden execution behavior.

Before installing or using this skill, treat it as a customer-data marketing playbook: use the smallest necessary export, prefer customer IDs over emails during analysis, store outputs securely, delete temporary datasets when done, and verify consent, opt-outs, suppression lists, and applicable marketing/privacy laws before email, SMS, phone, or ad-audience activation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly instructs users to export and process customer-level order data using direct identifiers such as Customer ID or email, but it provides no privacy, minimization, retention, or access-control guidance. This can lead users to handle personally identifiable information unnecessarily, increasing the risk of accidental disclosure, over-collection, or noncompliant downstream use during segmentation and campaign planning.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The playbook explicitly recommends SMS, phone calls, and personal outreach to lapsed customers without any mention of consent, opt-in status, quiet hours, or applicable privacy/marketing laws. In a customer segmentation and campaign skill, these omissions can lead users to run non-compliant outreach campaigns that violate TCPA, CAN-SPAM, GDPR, or similar regulations, exposing the business to complaints, fines, and reputational damage.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.