Back to skill

Security audit

Lead Gen Website Builder (SEO PUR)

Security checks for vulnerabilities and agentic risk

Overview

This is a real lead-generation website skill, but its generators and contact form have production-impacting safety gaps that users should review before installing.

Review before installing or using in production. Do not run the page generator on JSON or templates you did not author and trust; first add filename containment checks, schema validation, and context-aware escaping or structured rendering. Remove console logging of lead data, implement a real HTTPS submission backend, and show success only after confirmed delivery. Treat the bundled French/RGPD content as a starting point that still needs jurisdiction-specific legal and privacy review.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/generate_pages_batch.py:28
Finding

Arbitrary File Overwrite Through Output Filename Path Traversal

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/generate_pages_batch.py:22
Finding

Generated TypeScript and TSX Code Injection Through Unescaped Template Substitution

Content
View full analysis
{{CONTENT}}
); } ``` ### Technical Analysis The generator performs unrestricted textual replacement rather than context-aware serialization. Input values can be inserted into several distinct language contexts: - TypeScript identifiers, such as `COMPONENT_NAME` - Quoted JavaScript strings, such as `TITLE` and `DESCRIPTION` - JSX child expressions, such as `CONTENT` - URL and template-literal contexts No schema validation, identifier validation, string escaping, or JSX sanitization is applied. A crafted value can terminate its intended syntax and add imports, JSX elements, JavaScript expressions, event handlers, or other executable source. This is more severe than ordinary display-content injection because the attacker-controlled value becomes part of the trusted project source and is subsequently processed by the TypeScript/React build chain. ### Attack Path 1. An attacker supplies or modifies a p ...[truncated 1279 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/create_seo_files.py:12
Finding

Sitemap and Robots Content Injection Through Unvalidated SEO Metadata

Content
View full analysis
\n' xml_header += '\n' urls = [] for page in pages: url = page.get('url', '/') priority = page.get('priority', '0.5') urls.append(f' https://{domain}{url}{priority}') ``` ### Technical Analysis The `domain`, `url`, and `priority` values are copied directly into generated output without format validation or XML escaping. In `sitemap.xml`, characters such as `<`, `>`, and `&` can terminate existing elements, add attacker-controlled XML nodes, or make the document malformed. The `priority` value can similarly escape its element because it is not constrained to the sitemap priority format. In `robots.txt`, a domain containing newline characters can inject additional crawler directives. Although the documented usage assumes legitimate project metadata, the script does not enforce that trust boundary. ### Attack Path 1. An attacker supplies or modifies the domain argument or `pages.json`. 2. The attacker inserts XML markup into a page URL or priority, or newline-delimited directives into the domain. 3. A user or Agent runs: ```bash python create_seo_files.py domain pages.json output_dir/ ``` 4. The script concatenates the malicious value directly into `sitemap.xml` or `robots.txt`. 5. T ...[truncated 728 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
templates/component-ContactForm.tsx:31
Finding

Personal Lead Information Logged in Plaintext and False Submission Confirmation

Content
View full analysis
{ e.preventDefault(); console.log("Form submitted:", formData); toast.success("Message envoyé ! Nous vous recontacterons rapidement."); setFormData({ name: "", phone: "", email: "", message: "", utm_source: "", utm_campaign: "", utm_adset: "", utm_ad: "" }); }; ``` The logged state includes: ```tsx const [formData, setFormData] = useState({ name: "", phone: "", email: "", message: "", utm_source: "", utm_campaign: "", utm_adset: "", utm_ad: "", }); ``` ### Technical Analysis The contact form logs the complete lead record to the browser console. This includes personally identifiable information such as names, telephone numbers, email addresses, free-text messages, and advertising-attribution parameters. Browser console output may remain available for the page session and can be captured by local users, browser instrumentation, extensions, automated test systems, remote debugging tools, or support diagnostics. The handler also displays a success message even though it does not transmit the request to a backend or verify delivery. This creates a misleading state in which the visitor believes personal data was successfully delivered while it was only written to the local console and then removed from component state. ### Attack Path 1. A visitor enters a name, telephone number, email address, and message. 2. The visitor submits the form. 3. `handleSubmit` writes the complete `formData` object to the browser console. 4. A person or tool with access to console output, debugging data, or browser instrumentation reads or captures the record. 5. The visitor receives a false success notification despite no confirmed server-side submission. ### Impact Assessment The i ...[truncated 570 chars]
Remediation
View remediation
{ e.preventDefault(); try { const response = await fetch("/api/leads", { method: "POST", headers: { "Content-Type": "application/json" }, body: JSON.stringify(formData), }); if (!response.ok) { throw new Error("Lead submission failed"); } toast.success("Your request was submitted successfully."); setFormData(initialFormData); } catch { toast.error("Your request could not be submitted. Please try again."); } }; ``` The corresponding server endpoint must perform independent validation and must not trust client-side checks. ]]>
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (33)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a broad website-generation and compliance capability, including multi-page site creation, SEO optimization, conversion tracking, analytics, structured data, and RGPD compliance. The actual code chunk is much narrower: it simply creates robots.txt and sitemap.xml files from supplied inputs. While this fits a small part of 'SEO optimization,' it does not support the larger declared purpose and omits most of the described functionality. There is no evidence of undeclared harmful behavior, but there is a clear description-versus-behavior mismatch because the code only implements a limited SEO file generation utility rather than a complete local lead generation website builder.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The code chunk is a narrow utility that transforms an input JSON spec into a Markdown outline of site content. While this loosely relates to website planning and includes some SEO-related fields like title, meta description, and H1, it does not implement the declared end-to-end capability of building complete local lead generation websites. It also lacks any functionality for conversion tracking, analytics, structured data generation, or RGPD compliance. The actual behavior is substantially narrower than the declared purpose, so this is a material description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description promises a full local lead-generation website builder with SEO, analytics/conversion tracking, structured data, and RGPD compliance features. The supplied code only implements a generic batch templating utility: it loads a template and JSON data, replaces placeholders, and writes output files. While batch page generation could support website creation, the primary behavior here is much narrower and lacks the key advertised capabilities. This is a material description-behavior mismatch.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 121)May include surrounding context.

md
**Header** (`templates/component-Header.tsx`):

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 317)May include surrounding context.

md
**Header** (`templates/component-Header.tsx`):

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README promotes conversion tracking and UTM collection for lead generation workflows but does not explicitly warn about personal data implications, lawful basis, consent requirements, or data minimization. In the context of local lead-gen sites that collect contact details and marketing attribution, this omission can lead implementers to deploy privacy-impacting tracking in a non-compliant way.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill instructs collection of UTM attribution parameters in the contact form and says they can be sent to a backend/CRM, but it does not require a clear user-facing notice, consent basis, or data-minimization rules. In a lead-generation and GDPR context, silent capture and downstream transmission of tracking metadata can create privacy, compliance, and trust risks, especially when linked to personal contact details.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document explicitly recommends collecting personal data through forms and capturing UTM parameters for attribution, but it does not pair that guidance with any privacy notice, consent, retention, or lawful-basis requirements. In a lead-generation skill that also claims RGPD compliance, this omission can lead builders to implement tracking and contact collection in a way that violates privacy expectations and data protection obligations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This file contains user-facing instructional content exclusively in French, which can violate language/locale policy when no opt-in, alternative language, or explicit regional justification is provided. The content appears generally applicable rather than clearly limited to a French-speaking or region-specific compliance context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document directs operators to collect customer photos/videos and maintain weekly conversation logs containing location, symptoms, objections, and entry-page tracking data, but it does not provide any data-minimization, consent, retention, access-control, or redaction guidance. In a WhatsApp-based lead qualification workflow, these materials can contain personal data and even sensitive contextual details about a person's home, creating privacy, compliance, and data-handling risk if reused for SEO/Ads insights.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The generated content headings and labels are hard-coded in French, which imposes a specific language/locale on all output. The file does not offer a user opt-in or configuration for language selection, nor does it document a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The form collects personal data and marketing attribution fields in a lead-generation/RGPD-oriented context, but the submission handler only writes the data to the browser console and clears the form. This creates a misleading data-handling flow that can result in lost leads and non-compliant processing expectations, especially because users are induced to submit contact information without any real backend processing or privacy handling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The handler logs user-supplied personal data including name, phone, email, message, and UTM metadata to the browser console. Console logging of PII can expose sensitive data to anyone with local browser access, shared-device users, support/debug tooling, or captured logs, and it is especially problematic in an RGPD/compliance-oriented lead form.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The success toast states that the user will be contacted soon, but no request is sent, stored, or queued anywhere. In a lead-capture website, this is dangerous because it deceives users into believing a service request was received when it was silently discarded, potentially causing business loss and privacy/compliance complaints.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This component presents all user-facing consent text and actions in French only, including the banner title, description, and buttons. That can violate language/locale policy when no user opt-in or documented regional scope is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The visible UI labels are hard-coded in French (for example, 'Contacter via WhatsApp' and 'Appeler maintenant') without any indication that the skill is French-only or that users can choose a language. This is a natural-language locale policy concern because the file imposes a specific language by default.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

Le README indique que des images sont générées puis stockées dans /home/ubuntu/webdev-static-assets/, ce qui décrit une opération d'écriture sur le système de fichiers. Le document n'indique pas explicitement ce comportement comme potentiellement modifiant l'environnement local ni ne conseille de vérifier le contenu existant ou les permissions avant exécution.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

La ligne indique que les templates sont en français et seulement 'facilement traduisibles', ce qui suggère une langue par défaut imposée plutôt qu'un choix explicite offert à l'utilisateur. La politique demande de signaler les contraintes de langue ou de locale lorsqu'elles ne sont pas présentées comme un opt-in ou comme une limitation clairement justifiée.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The overview line introduces French-language requirements and phrasing ('avec garde-fous anti-spam', etc.), and later sections continue using French-specific terminology and deliverables. Because the skill does not explicitly offer a language/locale choice, it may impose a specific language or locale convention without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file contains operational guidance exclusively in French, and there is no note that the skill is intended only for French-speaking users or that another language can be selected. Under the policy for natural-language violations, forcing a specific language without opt-in can be a locale policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The examples for value propositions and CTA text are written in French, which can imply a fixed language preference in skill guidance. Because the file does not state that it is intended only for a French-speaking or region-specific audience, this may conflict with the policy against forcing a specific language without user opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file contains user-facing instructions exclusively in French, starting with 'Objectif' and continuing throughout the playbook. Under the policy rule for natural-language violations, forcing a specific language without opt-in can be a locale-policy issue when no justification or language choice is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

Line L31 states "Legal Mentions (Required in France)" in a generally titled compliance guide, which introduces a jurisdiction-specific requirement without clearly limiting the document's scope to France-only use. This can be read as imposing a locale-specific policy on all users of the skill content rather than offering it as a conditional requirement based on deployment region.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The document title, instructions, and copy/paste message are all in French, and the template at L13-L18 assumes French-only interaction. Per SQP-3, forcing a specific language without user opt-in can violate language/locale policy unless the regional limitation is explicitly documented and justified, which is not stated here.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.