Back to skill

Security audit

AI Chief Growth Officer

Security checks for vulnerabilities and agentic risk

Overview

This is a growth-consulting skill with disclosed memory and knowledge-base behavior, and I found no hidden code execution, exfiltration, or deceptive behavior.

Install only if you are comfortable sharing business metrics with the skill during growth planning. Confirm any proposed writes to kb.md or router-signals.md, and avoid storing confidential customer data, company-specific strategy, or raw financial details unless you intentionally approve that retention.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README explicitly states that each conversation can be accumulated into a knowledge base and references persistence to kb.md, but it does not provide a user-facing notice, consent flow, retention policy, or data-handling limits. This is dangerous because users may disclose sensitive business metrics, customer data, or strategic plans under the assumption of ephemeral processing, and that information could be retained and reused later.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documented trigger phrases include broad, natural-language business terms such as '增长策略' and '怎么提升转化', which can cause the skill to activate in contexts where the user did not intend to invoke this capability. In a multi-skill agent environment, overbroad activation increases the risk of misrouting, unnecessary exposure of user context to this skill, and accidental execution of growth-planning behavior when another tool would be more appropriate.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The router uses broad English keywords such as "build," "design," "improve," and "optimize" that are common in ordinary conversation, which can cause the skill to activate outside its intended scope. In a multi-skill environment, this increases the chance of misrouting user requests, causing inappropriate data collection, incorrect business advice, or unintended execution of this skill's logging and memory behaviors.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly instructs persistent logging, execution tracing, assumption tracking, and state retention across turns, but does not clearly require user notice, consent, retention limits, or data minimization. This is dangerous because users may provide business-sensitive metrics or strategic information that is stored and reused without transparent boundaries.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The session memory schema stores industry, stage, budget, CAC, LTV, past outputs, execution logs, assumptions, and user satisfaction across turns without any controls on sensitive content, scope, or lifespan. In a growth-consulting context, these fields can reveal commercially sensitive financial and operational data, making over-collection and indefinite retention materially risky.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The optimization protocol directs the system to write conversation-derived decisions, industry data, success and failure patterns, and routing signals into persistent knowledge files. Even with a note that user confirmation is needed, the design still operationalizes conversion of user-supplied content into long-lived knowledge artifacts, which can leak confidential business information or embed sensitive data into reusable system memory.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown knowledge-base file is written entirely in Chinese and provides no indication that language selection is optional or limited to a justified region-specific context. Under the policy rule for natural-language violations, forcing a specific language without user opt-in can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The routing phrases are broad, generic terms like "build," "optimize," and "what should we do," which are common in ordinary conversations and can easily trigger this skill outside its intended scope. In an agent-routing context, this can cause misclassification, inappropriate skill activation, and downstream execution of growth-oriented workflows on unrelated user requests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
70% confidence
Finding

Core headings, trigger phrases, usage instructions, and operational descriptions are all presented in Chinese, and the trigger mechanism relies on Chinese-language phrases. There is no indication that users may interact in other languages or that the Chinese-only orientation is a documented, justified regional constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

Natural-language metadata and section text are written in Chinese, and the file does not indicate that users may opt into another language or locale. This can conflict with language-choice policies when a skill is not explicitly documented as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This markdown file is entirely written in English and does not indicate that English is optional or required for a justified regional context. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.