Back to skill

Security audit

Map Customer Micromoments Across Web Analytics & CRM Platforms

Security checks for vulnerabilities and agentic risk

Overview

This skill is not malicious, but it handles sensitive customer profiling data and can push segments or workflow actions into external systems with weak privacy and approval scoping.

Review this skill before installing if you plan to connect it to Slack, CRM, support, or marketing systems. Use it only with data you are allowed to process, minimize exported fields, keep workflow actions human-approved, and do not rely on its compliance claim without your own privacy review.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
The skill is presented as an analysis tool, but the documentation also promotes real-time Slack alerts, CRM enrichment, and workflow/export actions that can trigger downstream operational behavior. This broadens the trust boundary from passive analytics to active routing of sensitive customer insights into third-party systems, increasing privacy, misuse, and unintended automation risk.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The safety section claims the skill does not make automated decisions, yet earlier sections instruct automated escalation, Slack alerts, workflow sync, and segment assignment. This contradiction can mislead operators into underestimating the degree of automation and may cause sensitive customer classifications to drive actions without adequate review.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill processes support tickets, emails, chat logs, comments, customer IDs, and emails, then recommends exporting results to Slack, HubSpot, WordPress, Google Sheets, Intercom, Zapier, and Make. Failing to clearly warn about sensitive data handling and third-party transfer exposes users to privacy, confidentiality, and compliance risks, especially because the data includes emotional profiling and buying-readiness inference.

Natural-Language Policy Violations

Medium
Confidence
97% confidence
Finding
The documentation asserts blanket GDPR/CCPA/privacy-law compliance without defining scope, legal basis, controls, or user responsibilities. Such unsupported compliance claims can cause users to rely on the skill in regulated contexts without implementing required consent, purpose limitation, regional transfer, data subject rights, or profiling safeguards.

Static analysis

No suspicious patterns detected.