Back to skill

Security audit

New Visitor Cold Start

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed ecommerce marketing-advice skill with no executable code, persistence, credential use, or hidden data access, though its popup and behavioral-targeting tactics need privacy and UX review before use.

Before installing, treat this as a marketing playbook that may recommend behavioral targeting, exit-intent popups, and mobile navigation-intercept tactics. Use it only where your consent, privacy, platform, and consumer-protection requirements are understood, and prefer easy dismissal and less intrusive timing triggers where possible.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The description contains broad trigger phrases such as 'cold-start offers for new visitors' and 'first-purchase coupons tied to what they viewed,' which can overlap with common ecommerce optimization requests. That increases the chance this skill is invoked when a user did not explicitly ask for behavioral targeting or offer-generation, causing unintended routing and execution of persuasive marketing logic.

Vague Triggers

Medium
Confidence
97% confidence
Finding
The 'Pushy when vague' instruction tells the agent to produce a full recommendation chain even when the user only provides a broad request. This weakens user-intent checking and can cause the skill to act on underspecified prompts, leading to overconfident personalization advice, unsolicited incentive design, or misapplication in contexts lacking consent/compliance details.

Missing User Warnings

Low
Confidence
89% confidence
Finding
The playbook explicitly suggests using back-button intercept on mobile, which can manipulate navigation flow and may violate user expectations or platform/legal requirements if deployed without prominent disclosure and consent considerations. Although the text says 'careful with UX/legal,' that warning is vague and does not provide safeguards, making it a real dark-pattern/privacy-compliance risk in a marketing implementation context.

Static analysis

No suspicious patterns detected.