Back to skill

Security audit

Store Policy Writer

Security checks for vulnerabilities and agentic risk

Overview

This skill is a document-drafting aid for ecommerce store policies, with no executable behavior or hidden data access in the artifacts.

Safe to use as a drafting aid. Review generated policies against your actual operations, marketplaces, privacy practices, and local legal obligations before publishing, especially for regulated products or cross-border sales.

Vulnerability Patterns
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Memory Manipulation

High
Category
Memory Poisoning
Content
- [ ] Data collected, purposes, and sharing are disclosed.
- [ ] GDPR rights covered if serving EU/UK; CCPA/CPRA rights if serving California.
- [ ] Cookie consent behavior matches the markets served.
- [ ] Clear statement on whether personal information is sold.
- [ ] Retention and security addressed.

## Terms of service
Confidence
80% confidence
Finding
Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Static analysis

No suspicious patterns detected.