Back to skill

Security audit

Content Marketing for Founders

Security checks for vulnerabilities and agentic risk

Overview

This is a content-marketing guidance skill with no executable code, data access, persistence, or hidden high-impact behavior found.

Install only if you want an opinionated content-marketing assistant, including Web3/crypto examples. Be aware it may activate on broad content or crypto mentions and may answer partly in Spanish unless you specify your preferred language.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/banner.svg (reported line 19)May include surrounding context.

text
<rect width="680" height="420" fill="white" rx="8"/>

  <!-- Top accent bar -->
  <rect x="0" y="0" width="680" height="4" fill="#1D9E75" rx="0"/>

  <!-- Grid lines -->

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/banner.svg (reported line 36)May include surrounding context.

text
<!-- Divider -->
  <line x1="40" y1="152" x2="640" y2="152" stroke="#e5e5e5" stroke-width="0.5"/>

  <!-- Badges -->
  <rect x="40" y="164" width="102" height="24" rx="4" fill="#E1F5EE" stroke="#0F6E56" stroke-width="0.5"/>
  <text x="91" y="181" text-anchor="middle" font-family="ui-sans-serif, system-ui, sans-serif" font-size="11px" font-weight="500" fill="#085041">Web3 / crypto</text>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/banner.svg (reported line 65)May include surrounding context.

text
<text x="444" y="262" font-family="ui-sans-serif, system-ui, sans-serif" font-size="12px" fill="#185FA5">Hooks, posts, captions</text>
  <text x="444" y="276" font-family="ui-sans-serif, system-ui, sans-serif" font-size="12px" fill="#185FA5">per platform</text>

  <!-- Row 2 cards -->
  <rect x="40" y="300" width="182" height="68" rx="6" fill="#FAEEDA" stroke="#854F0B" stroke-width="0.5"/>
  <text x="56" y="324" font-family="ui-sans-serif, system-ui, sans-serif" font-size="14px" font-weight="500" fill="#412402">Repurposing Engine</text>
  <text x="56" y="342" font-family="ui-sans-serif, system-ui, sans-serif" font-size="12px" fill="#854F0B">1 piece → 9 formats,</text>

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README states the skill activates automatically on broad keyword mentions like crypto, Web3, DeFi, NFTs, or blockchain, which can cause the skill to trigger outside the user's intended task scope. This is not inherently malicious, but it increases the chance of inappropriate routing, irrelevant prompt injection surface, or accidental use of a specialized module when the user only mentions the topic in passing.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases are broad enough to match generic requests like 'help me with my content' or 'write a post for me,' which can cause the skill to activate outside the user's actual intent. This is dangerous because unintended invocation can override more appropriate skills, degrade routing accuracy, and lead to irrelevant or misleading outputs in multi-skill environments.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill mandates a Spanish prompt for tone selection without checking the user's preferred language. This can create unexpected language switching, confuse users, and produce unusable output for English-only interactions, which is a quality and safety issue in agent behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

These instructions repeatedly require Spanish-language output elements and examples without offering locale choice or fallback behavior. Repeated forced language behavior increases the chance of non-compliant, confusing, or inaccessible responses, especially when the surrounding skill is otherwise written for general use.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instruction to load this file for 'any user operating in crypto, Web3, DeFi, NFTs, blockchain, or fintech' is very broad and lacks boundaries or exclusion conditions. Terms like 'fintech' and 'operating in' are expansive enough to overlap with many general business or technology contexts, increasing the chance of unintended invocation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The audience table specifies 'Spanish-speaking LATAM' and directs a particular tone and framing for that group, and a later section reinforces a 'Spanish-language crypto education' regional voice. Because the file presents this as prescribed language behavior without mentioning user preference or opt-in, it creates a potential language/locale policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.