Back to skill

Security audit

Personal Branding & Authority Building

Security checks for vulnerabilities and agentic risk

Overview

This is a text-only personal branding guidance skill with a broad auto-activation setting, but no code, credential access, posting automation, or hidden harmful behavior.

Installers should understand that this skill may be active broadly because of always:true, so it could shape responses outside narrowly phrased branding requests. The content itself is advisory and text-only; users should still manually review any public posts, legal claims, company metrics, or employment-transition advice before acting.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Hidden Instructions

High
Category
Prompt Injection
Content
# Personal Branding & Authority Building

A comprehensive skill for developing personal brands and building professional authority for B2B SaaS professionals.
Confidence
60% confidence
Finding
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The README says to 'Simply mention personal branding tasks' and gives examples like 'Help me define my personal brand positioning,' then states Claude will 'automatically use this skill.' This is an ambiguous trigger description without clear boundaries, exclusions, or a precise invocation scope, which could cause unintended activation from ordinary conversation about branding.

Vague Triggers

Medium
Confidence
97% confidence
Finding
The manifest sets `always:true`, which causes the skill to activate without scoped trigger constraints. That broadens the circumstances under which its guidance can influence an agent and increases the chance of unintended invocation, prompt interference, or misuse outside the intended personal-branding context.

Autonomous Decision Making

Medium
Category
Excessive Agency
Content
This determines everything else about your personal branding strategy.

### Founder Personal Brand:
- Full autonomy (no approval needed)
- Personal = company brand (tightly coupled)  
- Can be contrarian (if industry allows)
- High risk, high reward
Confidence
75% confidence
Finding
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Autonomous Decision Making

Medium
Category
Excessive Agency
Content
Standard Post (Industry Insight):
Draft → Publish (same day)
No approval needed

Company Metrics/Wins:
Draft → Manager Slack → Approval → Publish (few hours)
Confidence
75% confidence
Finding
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Autonomous Decision Making

Medium
Category
Excessive Agency
Content
Standard Post (Industry Insight):
Draft → Publish (same day)
No approval needed

Company Metrics/Wins:
Draft → Manager Slack → Approval → Publish (few hours)
Confidence
75% confidence
Finding
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Autonomous Decision Making

Medium
Category
Excessive Agency
Content
Timeline: 1-2 weeks (expect this at large companies)

Only Safe Posts (No Approval):
- Pure industry insights
- Personal career reflections
- Sharing other people's content
Confidence
75% confidence
Finding
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Static analysis

No suspicious patterns detected.