Back to skill

Security audit

Generate Micro-Moment Copy with AI — Instant Marketing Content

Security checks for vulnerabilities and agentic risk

Overview

This skill is a marketing-copy assistant with disclosed AI and analytics-key configuration; its main risk is privacy care when users provide segment or behavioral data.

Before installing, treat this as a content-generation skill that may send supplied campaign context to AI providers. Use anonymized or aggregated segment data where possible, avoid sensitive personal attributes, and review generated scarcity, urgency, health, financial, or compliance-related claims before publishing.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The skill explicitly encourages use of user segment and behavioral data for personalization, but it does not present a clear up-front warning to the operator about handling potentially sensitive or regulated data. In a marketing context, this can lead users to input purchase history, inactivity status, or other profiling attributes into external model providers without informed consent, minimization, or legal review.

Static analysis

No suspicious patterns detected.