Back to skill

Security audit

Promo Stack

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed planning aid for promo inventory, ad pacing, pre-order copy, and supplier messaging, with no executable code or hidden account access found.

Use this as a decision-support and drafting skill. Before publishing pre-order copy, pausing ads, or contacting suppliers, confirm current inventory data, thresholds, approval owners, customer-service policy, and regional pre-order disclosure rules.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger criteria are extremely broad and include many loosely defined phrases such as low inventory, ads still running, oversell risk, pacing, and multi-channel sync. This increases the chance the skill is invoked in situations outside its intended scope, causing inappropriate automated messaging or operational guidance during sensitive promo workflows.

Static analysis

No suspicious patterns detected.