Back to skill

Security audit

Phy Twitter X Gtm

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Twitter/X marketing strategy guide with no code, persistence, credential access, or hidden privileged behavior.

Installers should expect this skill to guide Twitter/X content planning and may want to clarify target language, audience, and whether web research should use only public sources. It should not be given account credentials or permission to post automatically unless a separate trusted workflow controls that.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger description includes a broad catch-all phrase for any Twitter/X marketing planning, which can cause the skill to activate in situations beyond its intended scope. Overbroad activation increases the chance of unintended invocation, context hijacking, and irrelevant or lower-quality outputs, especially in multi-skill agent environments where skill selection determines what instructions are applied.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The examples show Chinese-language user requests receiving English-only outputs without asking for the user's preferred language. This can lead to language mismatch, user confusion, and accidental generation of content unsuitable for the user's audience or intent, particularly when localization and audience targeting are important to safe and accurate communications.

Static analysis

No suspicious patterns detected.