Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md API_KEY"],"bins":["python3","curl"]},"os":["macos","linux","win32"],"files":["SKILL.md"],"emoji":"📊"}}
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a competitor-research prompt guide that uses expected platform APIs and optional exports, with some secret-handling and data-sharing cautions users should understand.
Install only if you are comfortable connecting external API keys and optionally sending generated reports to services such as Slack or Google Sheets. Store keys in a secure environment or secret manager, avoid committing them to repositories, use least-privilege credentials where possible, and review report contents before exporting sensitive business strategy or internal notes.
Referenced artifact was not completely inspected
API_KEY"],"bins":["python3","curl"]},"os":["macos","linux","win32"],"files":["SKILL.md"],"emoji":"📊"}}
The skill advertises exports to Slack, Google Sheets, Notion, and a CMS without clearly warning users that collected competitor analysis data may be transmitted to third-party services. This creates a meaningful risk of unintended data disclosure, especially if users include proprietary notes, internal strategy, or sensitive research in the generated reports.
The setup section instructs users to store multiple API keys and a Slack webhook URL but does not warn about secret handling, scope limitation, rotation, or avoiding exposure in logs and repositories. Poor secret hygiene can lead to credential leakage, unauthorized API use, spam via Slack webhooks, and broader compromise of connected services.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
- Copy API key to `SERPER_API_KEY`
5. **Enable Slack Integration** (Optional):
- Create a Slack incoming webhook: [Slack Apps](https://api.slack.com/apps)
- Copy webhook URL to `SLACK_WEBHOOK_URL`
### Configuration Options
No suspicious patterns detected.