Back to skill

Security audit

Monitor Content Decay & Score Refresh Opportunities Automatically

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent content-audit helper, but users should handle connected marketing data and credentials carefully.

Before installing, confirm which services you will connect, use least-privilege API credentials, avoid pasting secrets into shared prompts or files, and review/redact audit results before sending them to Slack or other third-party tools.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly supports sending audit results to Slack, which is a third-party service, but provides no warning that URLs, performance metrics, and content-prioritization data may leave the user's primary environment. This creates a real data-handling and privacy risk, especially if reports contain sensitive internal URLs, unpublished content references, or proprietary marketing performance data.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs users to provide and store multiple sensitive credentials, including API keys and a WordPress application password, without any guidance on secure secret handling. This is dangerous because users may place secrets directly in shell history, plaintext files, prompts, or shared environments, increasing the chance of credential leakage and unauthorized access to analytics, search, CMS, and messaging systems.

Static analysis

No suspicious patterns detected.