Back to skill

Security audit

Marketing Psychology

Security checks for vulnerabilities and agentic risk

Overview

This is a marketing advice skill with persuasion content, but it has no executable code, hidden install behavior, persistence, or data exfiltration path.

Install only if you want marketing psychology guidance. Treat its persuasion advice as strategy input, and require truthful claims, genuine scarcity, transparent pricing, and consent-preserving defaults when applying it.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill description is extremely broad and includes many common terms like 'psychology,' 'decision-making,' and 'persuasion,' which can cause the skill to trigger for requests outside a clearly bounded marketing context. Over-broad activation increases the chance that manipulative or sensitive advice is inappropriately surfaced in unrelated conversations, expanding exposure to risky persuasion guidance.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This section teaches multiple persuasion and choice-architecture techniques, including urgency, defaults, anchoring, decoys, loss aversion, and contrast, but does not include a prominent, enforceable safety boundary against deceptive, coercive, or exploitative use. Although the document occasionally uses words like 'ethically' or 'only use when genuine,' those cautions are inconsistent and insufficient relative to the breadth of manipulative tactics described.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The eval explicitly expects the skill to trigger on vague, casual phrasing rather than on clearly bounded marketing-psychology intent. That broadens activation criteria and can cause the agent to invoke this skill for everyday requests that merely mention 'psychological principles,' increasing inappropriate routing and persuasive-response overreach. In a marketing-persuasion skill, this is more dangerous because mistaken activation can steer benign copy/help requests into manipulation-oriented advice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.