Back to skill

Security audit

Mktclaw

Security checks across malware telemetry and agentic risk

Overview

This is a mostly read-only Chinese marketing planning skill; it has stale and overbroad documentation, but I found no artifact-backed exfiltration, destructive behavior, or hidden credential use.

Install only if you want a Chinese marketing-agency assistant. Do not provide PII, raw customer-level data, credentials, wallet details, or sensitive financial records. Keep any Campaign Vault data local and aggregated, manually review crisis PR outputs before publishing, and get professional review for medical-aesthetic, finance, education, or other regulated marketing claims.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (14)

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
The skill explicitly recommends '场控控评' in response to negative comments, which goes beyond ordinary livestream operations into reputation-shaping and suppression tactics. In a marketing/live-commerce context, this can facilitate deceptive moderation practices, hide legitimate consumer complaints, and encourage operators to manipulate audience perception during a commercial transaction.

Description-Behavior Mismatch

Medium
Confidence
89% confidence
Finding
The eval suite for a marketing skill expands into runtime telemetry, learning engines, versioning, and gate-control automation, which materially broadens the skill’s operational scope beyond its stated purpose. This kind of scope creep is dangerous because it can normalize collection of execution metadata and introduce higher-privilege engineering behaviors that were not clearly justified by the user-facing marketing function.

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
The tests require self-evolution features such as learning-engine pattern extraction, knowledge-base updates, and automatic version bumping, which creates a pathway for the skill to modify its own behavior or supporting assets over time. In a marketing skill context, that is risky because self-modifying or self-updating mechanisms can bypass normal review processes, amplify prompt-induced drift, and make later behavior less predictable and less auditable.

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
The suite introduces persistent Campaign Vault storage, deletion-right handling, and multi-tenant isolation requirements, meaning the skill is expected to participate in user data retention and governance rather than only generate marketing deliverables. This is dangerous because once persistent storage and tenant separation are in scope, failures can lead to privacy violations, cross-client data leakage, or noncompliance with deletion obligations.

Intent-Code Divergence

High
Confidence
97% confidence
Finding
The note '明确"医美非医疗"' contradicts the rest of the document, which correctly treats aesthetic medicine as a regulated medical service requiring medical licenses, physician credentials, and medical-ad review approvals. This misclassification can cause operators or downstream agents to bypass healthcare-specific legal, advertising, consent, and safety controls, creating substantial compliance and consumer-harm risk in a high-regulation domain.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The README advertises one-command self-evolution that can learn from production logs, update knowledge files, and automatically bump versions, but it does not clearly warn users that these operations may modify skill artifacts and operational behavior. In a skill context, undocumented self-modification increases the risk of unsafe drift, poisoned feedback ingestion, or unintended production changes being applied without informed human review.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The README describes a private multi-tenant Campaign Vault that stores campaign performance data by brand/BU, but it does not provide a clear user-facing warning at the point of description that user data may be retained and used for future operations. Because this skill handles marketing and potentially sensitive business data, ambiguous storage/retention messaging can lead to unintended collection, compliance gaps, and misuse across tenants if users are not properly informed.

Vague Triggers

High
Confidence
95% confidence
Finding
The description says the skill must trigger whenever users mention a very broad set of marketing-related topics, even if they do not explicitly ask for an agency. Overbroad activation can hijack unrelated conversations, cause the wrong skill to ingest sensitive context, and let the skill influence outputs outside its intended scope.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The router's trigger examples map broad keywords and semantics to agent roles without defining clear exclusion conditions or confidence thresholds. In practice, this can over-route user prompts into specialized marketing or crisis-playbook behavior, increasing the chance of unauthorized task capture, inappropriate advice generation, or exposure of internal prompts/resources in unrelated conversations.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The workflow description explicitly says it should auto-trigger in crisis PR scenarios and the broader skill metadata instructs activation on a wide range of marketing-related requests, even when the user does not clearly request an agency workflow. Over-broad activation can cause the system to route ordinary conversations into a high-impact PR delivery flow, producing authoritative crisis-response content without sufficient user intent verification or scoping.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The skill is written to operate in Chinese and does not appear to offer a user-language fallback or explicit language selection. This can cause user intent to be misunderstood, safety-critical nuances to be lost in translation, or compliance guidance to be delivered in a language the user cannot reliably understand, which is a real quality and safety issue even though it is not a direct exploit primitive.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
The document is written entirely in Chinese and frames itself as a shared framework for all agents, but it does not provide a user-locale check or an opt-in mechanism before shaping outputs around that language context. In a multi-user or multilingual assistant, this can cause the skill to override the user's preferred language, reduce transparency, and lead to unusable or misleading outputs for users who cannot read Chinese.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The workflow can be triggered by broad keywords like '全案', '一站式', 'from 0 to 1', and 'end-to-end', which are common phrases that may appear in many unrelated user requests. In a skill that automatically orchestrates multiple downstream agent roles, this can cause over-activation, unnecessary data propagation across branches, and delivery of actions the user did not explicitly request.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The workflow's checkpoint prompts and descriptions are hard-coded in Chinese, which can prevent non-Chinese-speaking users from understanding confirmations and safely validating intermediate outputs. In a multi-stage marketing workflow, misunderstood confirmations can result in accidental approval of plans, role outputs, or integrated deliverables the user did not intend to authorize.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.