Back to skill

Security audit

Track Content Attribution & Creator Credits Automatically

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for copyright monitoring, but it promotes automated legal enforcement and live website changes without clear approval gates or scope controls.

Install only if you are prepared to supervise it closely. Treat detection and reporting as safer defaults, and require manual approval before sending notices, filing takedowns, routing documents for signature, changing WordPress/server content, or running scheduled scans over large content libraries.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill explicitly promotes automatic enforcement actions and automatic website modifications such as injecting canonical tags, sending legal notices, and filing takedown-related workflows, but it does not present clear user-facing safety warnings, confirmation gates, or scope limitations. In an agent context, this can lead to unintended changes to production sites or external communications with legal and reputational consequences if triggered on incomplete, incorrect, or overbroad inputs.

Static analysis

No suspicious patterns detected.