Back to skill

Security audit

Audience Sentiment Intent Analyzer

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent marketing sentiment-analysis purpose, but it needs review because it encourages broad analysis of private DMs and email through external AI and report/Slack outputs without clear consent, redaction, or retention controls.

Review this skill before installing in any account with private customer messages. Use it only with read-only, source-specific access, explicitly opt in before DMs or email are analyzed, disable raw samples and Slack payloads for private content, and redact personal or confidential data before sending text to an external AI provider.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

other

Warning
Location
SKILL.md:19
Finding

Overbroad Collection and External Processing of Private Communications

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 19-26 and 121-140
Vulnerability Type: Sensitive data overcollection and third-party disclosure
Risk Level: Medium

Evidence

markdown
The skill automatically ingests comments, DMs, and replies from YouTube, TikTok,
Instagram, and email—then applies advanced NLP analysis to extract:

- **Intent signals**: Buying intent, pain points, feature requests, unmet needs
- **Sentiment velocity trends**: Identify whether audience sentiment is accelerating
  positive or negative over time
- **Emerging topics**: Flag discussion patterns before they trend publicly
- **Churn indicators**: Early warning signs of audience dissatisfaction or drift
- **Audience persona shifts**: Detect changes in who's engaging and why

Relevant configuration includes:

bash
# TikTok Business API (for comment/DM data)
export TIKTOK_ACCESS_TOKEN="your-tiktok-access-token"
export TIKTOK_BUSINESS_ACCOUNT_ID="your-account-id"

# Instagram Graph API (for comments and DMs)
export INSTAGRAM_BUSINESS_ACCOUNT_ID="your-instagram-business-id"
export INSTAGRAM_ACCESS_TOKEN="your-instagram-access-token"

# Anthropic Claude for NLP analysis
export ANTHROPIC_API_KEY="your-claude-api-key"

# Optional: Gmail for email feedback analysis
export GOOGLE_SERVICE_ACCOUNT_JSON="/path/to/service-account.json"

# Optional: Slack notifications for alerts
export SLACK_WEBHOOK_URL="https://hooks.slack.com/services/YOUR/WEBHOOK"

Technical Analysis

The declared sentiment-analysis functionality can legitimately require access to user-selected messages. However, the Skill encourages broad ingestion of comments, private direct messages, and email threads, as well as connecting all available platforms and analyzing substantial historical windows.

Private messages and email threads may contain names, contact details, account information, confidential business material, authent ...[truncated 2555 chars]

Remediation
View remediation

Remediation Suggestions

  1. Default to public comments from only the platform and time range explicitly requested by the user.
  2. Require separate, explicit approval before accessing DMs, email, or other non-public communications.
  3. Request read-only, source-specific OAuth scopes instead of broad account permissions.
  4. Present the intended data categories, recipients, time range, and estimated record count before collection.
  5. Redact names, email addresses, phone numbers, access tokens, authentication links, payment data, and unrelated message content before external processing.
  6. Prefer local aggregation or classification where possible; otherwise disclose the external model provider and obtain user approval before transmission.
  7. Set include_samples to false by default. If samples are necessary, use pseudonymized excerpts and require explicit opt-in.
  8. Define retention and deletion periods for source data, model requests, intermediate files, reports, and notification payloads.
  9. Prevent raw DMs or emails from being sent through Slack alerts; alerts should contain aggregate findings and links to access-controlled reports.
  10. Document recipient access controls, audit logging, encryption requirements, and applicable data-processing agreements.

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:390
Finding

Incomplete Privacy Guardrail Leaves Sensitive-Data Boundary Undefined

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 390
Vulnerability Type: Incomplete security and privacy policy
Risk Level: Low

Evidence

The file ends with an incomplete privacy guarantee:

markdown
- **No private data extraction**: Will not extract email addresses, phone numbers,

Technical Analysis

The sentence terminates at the end of the file without defining what other private data is protected, whether the restriction applies to collection, analysis, output, or external transmission, and what redaction controls enforce the promise.

This is particularly significant because the same Skill advertises analysis of DMs and Gmail threads. Merely stating that specific identifiers will not be “extracted” does not prevent raw messages containing those identifiers from being transmitted to an external model or copied into sample output.

This is an insecure specification and configuration practice. It is not evidence of malicious code, but it leaves implementations without a complete or enforceable privacy boundary.

Attack Path

  1. An Agent follows the Skill workflow to ingest private messages or email.
  2. The incomplete guardrail is interpreted narrowly as prohibiting only explicit structured extraction of email addresses and phone numbers.
  3. Raw text containing those identifiers is still processed externally or included in output samples.
  4. Sensitive information is exposed despite the apparent privacy assurance.

Impact Assessment

The incomplete rule can result in inconsistent implementations and accidental disclosure of contact details or other personal information. The scope is limited to data available through the configured social-media and email integrations. This issue does not grant operating-system access, code execution, persistence, or additional platform permissions by itself.

Remediation
View remediation

Remediation Suggestions

Replace the truncated statement with a complete, enforceable policy that:

  • Defines sensitive data categories, including contact details, credentials, financial information, authentication links, health information, and unrelated personal content.
  • Distinguishes collection, extraction, external transmission, storage, display, and notification.
  • Requires redaction before any third-party model request.
  • Prohibits credentials, secrets, and unnecessary identifiers in generated output.
  • Requires explicit consent for private-message and email analysis.
  • Specifies retention, deletion, access-control, and audit requirements.
  • Documents how violations are prevented technically rather than relying only on descriptive text.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 7)May include surrounding context.

md
C_API_KEY"],"bins":["python3","jq"]},"os":["macos","linux","win32"],"files":["SKILL.md"],"emoji":"📊"}}

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly handles private DMs and email threads but does not present a clear upfront warning that sensitive, non-public communications may be ingested and analyzed. This creates a real privacy and consent risk because users may run the skill on confidential customer content without understanding the exposure, retention, or downstream sharing implications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The configuration/output examples enable inclusion of sample comments in results, which can expose user-generated content from private or semi-private sources such as DMs, emails, and social replies. Without a warning or default redaction behavior, the skill may surface personal, sensitive, or reputationally damaging text into reports, logs, or shared channels like Slack.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 389)May include surrounding context.

md
### What This Skill Will NOT Do

- **No automated responses**: This skill analyzes sentiment and intent but does NOT auto-reply to comments or DMs. All response recommendations require human approval.
- **No deletion or moderation without approval**: The skill flags problematic content but requires explicit human authorization before any comment removal.
- **No private data extraction**: Will not extract email addresses, phone numbers,

Static analysis

No suspicious patterns detected.