Back to skill

Security audit

Atlas Conversion Rate Optimizer

Security checks for vulnerabilities and agentic risk

Overview

This is a mostly coherent CRO copywriting skill with some confusing pasted security-audit marketing text, but no code, install actions, persistence, credential handling, or hidden execution.

Before installing, treat this as a lightweight CRO/copywriting template skill. Be aware that some security-audit and DeFi references look copied from another product and may make the paid upgrade claims confusing, so verify any external paid offering separately.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The upgrade section advertises 'advanced DeFi modules,' a 'risk scoring rubric,' and other security-audit materials that are unrelated to a CRO/copywriting skill. This mismatch is dangerous because it can indicate copy-paste contamination, deceptive packaging, or hidden repurposing of the skill, which undermines user trust and may mislead users into invoking the skill for security-sensitive workflows it was not designed to handle.

Natural-Language Policy Violations

Low
Confidence
95% confidence
Finding
The markdown includes the Chinese text '验证 needed' within an otherwise English-language skill. This introduces a language/locale inconsistency without offering a user choice or explaining that multilingual output is intended.

Static analysis

No suspicious patterns detected.