Back to skill

Security audit

Competitive Intelligence & Market Research

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a markdown-only competitive research guide, but it includes a risky tactic to subtly ask competitor employees for pricing information.

Install only if you are comfortable using it as a research-template library and avoid the competitor-employee outreach tactic. Keep competitive research limited to public sources, first-party customer interviews, licensed research tools, and legally reviewed claims, especially for regulated sectors.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The guidance states specific language requirements such as 'Product: English + Hindi (minimum)' and 'Support: Hindi + regional languages' as defaults. This imposes a locale/language policy in natural language without offering user choice or clearly limiting the requirement to a narrowly justified region-specific deployment context.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly suggests contacting competitor employees to obtain pricing information 'subtly,' which can encourage deceptive social-engineering behavior to elicit non-public business information. In a competitive intelligence skill, that crosses from legitimate market research into ethically risky and potentially unlawful collection tactics, increasing legal, reputational, and policy risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.