Back to skill

Security audit

Newsletter Growth Hacker Pro

Security checks for vulnerabilities and agentic risk

Overview

This is a local newsletter marketing helper that analyzes user-provided metrics and content without hidden access, network use, or persistence.

Install only if a Chinese-language local CLI for newsletter growth planning fits your workflow. Review any marketing recommendations before acting on them, because the benchmarks and predictions are simple built-in heuristics rather than verified live platform analytics.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (15)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The code is clearly focused on analytics and reporting: calculating email KPIs, rating them against benchmarks, generating recommendations from those metrics, creating reports, tracking subscriber growth, and projecting future growth. These behaviors do align with the declared data analysis, trend tracking, and growth prediction portions. However, the declared description materially overstates the skill by claiming capabilities for acquisition strategy generation, content optimization, and A/B test subject-line generation, none of which appear in the supplied code. Because several prominent declared functions are absent and the implemented primary purpose is narrower than advertised, this is a description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The implemented code is narrowly focused on two functions: analyzing newsletter content with simple rule-based suggestions and generating subject lines/A/B test plans. It includes static open-rate benchmarks and hardcoded predicted ranges for subject-line styles, but no real analytics pipeline, no subscriber growth tracking, and no forecasting model. The declared description presents a broader 'growth hacker' tool covering acquisition strategy, data analysis, and growth prediction, which materially exceeds what this code chunk actually does. Therefore the description does not accurately represent the supplied code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The declared description presents a broad newsletter growth toolkit covering subscriber acquisition, content optimization, A/B subject line generation, data analysis, and growth prediction. The supplied code chunk does support subscriber acquisition guidance and a simple growth forecasting function, which align with part of the description. However, it does not implement content optimization features, does not generate A/B test subject lines, and does not analyze actual email marketing data. Its behavior is much narrower than the declared purpose, focusing specifically on acquisition strategies plus basic projections and action planning. This is a description-behavior mismatch due to materially missing declared capabilities, though there is no evidence of undeclared sensitive behavior or permission misuse.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file states '每个函数都有中文文档', indicating the skill's function documentation is in Chinese. This reflects a fixed language choice, and the document does not mention any user language selection or a justified region-specific requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The entire quickstart, prompts, examples, and troubleshooting guidance are written exclusively in Chinese, including the interactive menu and sample inputs. This imposes a specific language/locale on users without documenting an opt-in choice or a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The entire user-facing document is written in Chinese, and the feature list explicitly states '中文支持,适合中国市场', which indicates a locale-specific presentation without any opt-in or alternative language path. Under the policy rule, forcing a specific language is a natural-language policy concern unless the locale restriction is clearly documented and justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest description and primary README content are written entirely in Chinese, which effectively constrains the skill's interaction language for users without any opt-in or alternative locale guidance. The policy explicitly flags language or locale restrictions when the skill does not offer user choice or justify the constraint as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file is written entirely in Chinese and does not offer any language or locale choice, translation option, or justification that it is intended only for a Chinese-speaking or region-specific audience. Under the language/locale policy rule, a skill artifact that effectively forces a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The entire skill content is written as Chinese-only subject line templates and guidance, with no indication that users may choose another language or that the skill is intentionally restricted to a Chinese-language context. The policy requires flagging language or locale constraints when they are imposed without user opt-in or clear justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code file contains user-facing natural language and documentation in Chinese, including the module description and later CLI output, but does not indicate that Chinese is optional or that the tool is intentionally region-specific. Under the policy rule for language/locale, forcing a specific language without user opt-in is a violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring and user-facing descriptions force a specific language/locale experience in Chinese. The policy allows locale constraints only when the skill offers user opt-in or clearly documents a justified region-specific purpose, neither of which is present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This file presents the skill title, descriptions, prompts, and menu output exclusively in Chinese. The stated policy requires flagging language or locale constraints when the skill forces a specific language without user opt-in, and no alternative language selection or justification is provided here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This Python skill hard-codes Chinese natural-language descriptions and user-facing text, starting with the class docstring and continuing throughout the strategy content and CLI output. Because the file does not offer the user any language/locale selection or justify the Chinese-only behavior as region-specific, it violates the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file is entirely presented in Chinese starting from the title, with no indication that the user can choose another language or that the content is intended only for a Chinese-language audience. The policy explicitly calls for flagging language or locale constraints when they are imposed without user opt-in or clear justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This requirements file contains natural-language comments in both English and Chinese, including 'Python 依赖' and other Chinese labels, but does not indicate that the skill is intended specifically for Chinese-speaking users or offer any language/locale choice. Under the policy, forcing or assuming a language without opt-in can be a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.