Back to skill

Security audit

Siluzan TSO

Security checks across malware telemetry and agentic risk

Overview

The skill is coherent for TSO advertising work, but it needs Review because installation and some workflows grant broad persistent access and high-impact ad/account authority that users should explicitly understand.

Before installing, review the one-click installer effects carefully: it may change npm configuration, install global tooling, register the skill across multiple assistants, and store Siluzan credentials. Use it only in an environment where you are comfortable granting real advertising-account, campaign, report, and sensitive account-opening authority, and confirm every write/delete/publish action against the target account and data being submitted.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (52)

Tp4

High
Category
MCP Tool Poisoning
Confidence
81% confidence
Finding
If the skill actually auto-installs or upgrades Node.js, rewrites npm registry settings, globally installs packages, registers itself into assistant-wide skill directories, and performs login initialization, that exceeds the declared routing/reporting purpose and crosses into host-environment modification. This is dangerous because users invoking an ad-analysis skill would not reasonably expect persistent system changes, supply-chain exposure via external package sources, or authentication side effects.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
This file is presented as a read-only reference, but it includes numerous state-changing commands such as create, edit, delete, enable, pause, and bid changes. In an agent setting, that mismatch can cause automation to invoke destructive or billing-affecting actions under a read-only trust assumption, increasing the risk of unintended account modifications.

Intent-Code Divergence

High
Confidence
96% confidence
Finding
The opening text explicitly says this document is for read-only use, yet later sections instruct how to perform writes. That contradiction is dangerous because agents often rely on top-of-file scope statements for routing and safety decisions, so the file can bypass safeguards intended to restrict execution to non-mutating operations.

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
The template loads executable JavaScript from a remote third-party origin via a plain script tag. Because this report also injects dynamic report data into the page, compromise of that external host, DNS, CDN path, or supply chain would grant arbitrary script execution in every rendered report, enabling data theft, DOM manipulation, and silent exfiltration of account/report contents.

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
The template loads and executes JavaScript from an external domain at report render time, which creates a supply-chain and integrity risk: if the CDN, DNS, TLS termination, or hosted asset is compromised, arbitrary code runs in the context of the report. Because this report processes account analytics data and is intended as a local renderer, network-dependent script execution expands the trust boundary unnecessarily and could expose report data or alter displayed results.

Context-Inappropriate Capability

Low
Confidence
87% confidence
Finding
The template executes third-party JavaScript from external origins, including Tailwind CDN and ECharts, which grants those providers code execution in the context where the report is opened. In an agent skill that may render reports for users, this creates a supply-chain and content-integrity risk: a compromised CDN, malicious asset replacement, or hostile network environment could inject arbitrary script into the report page.

Description-Behavior Mismatch

Low
Confidence
92% confidence
Finding
The template is presented as a local/print reference, but it pulls executable JavaScript and CSS from multiple external domains at render time, including a third-party script host. If any upstream CDN or network path is compromised, opening the report can execute attacker-controlled code in the viewer's browser, alter report contents, or exfiltrate embedded report data. In an ad-reporting skill context, reports may contain account names, performance metrics, and potentially customer-sensitive business data, which makes supply-chain loading risk more meaningful than in a purely decorative page.

Description-Behavior Mismatch

Medium
Confidence
89% confidence
Finding
The installer invokes the CLI to register the skill into many global AI-assistant directories, affecting software beyond the narrow scope of installing one advertising-analysis tool. That broad cross-application persistence increases attack surface and can surprise users or administrators, especially because it is done automatically and forcefully (`--global --force`) without explicit consent.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The script downloads and installs Git for Windows from a vendor-controlled CDN as a fallback unrelated to the declared skill purpose. Installing extra executable tooling expands system trust to another binary supply chain and creates unnecessary execution capability, which is risky if the hosted installer is replaced, tampered with, or simply not expected by the user.

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
The installer adds auxiliary developer tooling solely to provide an agent-shell fallback path, not to satisfy the skill's advertised advertising/market-analysis function. Bundling unrelated tooling increases privilege and persistence opportunities on the host, and in this skill context it is less justified because the manifest describes business and analysis workflows rather than developer-environment setup.

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The installer force-registers the skill into many different assistants' global skill directories, expanding persistence and execution surface far beyond what is needed to install a single CLI. In the context of an advertising/analysis skill, this cross-platform propagation is unnecessary and increases the chance of unintended activation, trust boundary violations, and broad user-environment modification.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The script changes the user's global npm registry to `https://registry.npmmirror.com`, which alters package resolution for all future npm operations, not just this install. This is dangerous because it silently changes a global trust source and can affect unrelated software supply-chain integrity and reproducibility.

Vague Triggers

High
Confidence
89% confidence
Finding
The trigger conditions are extremely broad, covering generic requests like industry reports, market analysis, diagnosis, reports, and even mixed phrases that may arise outside the intended advertising context. Overbroad auto-loading is dangerous because it can cause the skill to seize unrelated conversations, invoke privileged CLI workflows unnecessarily, and steer the agent into higher-risk tool use without clear user intent.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill explicitly instructs the agent to persist customer context and generated reports to local files, but it does not require any user notice, consent, retention limits, or handling rules for potentially sensitive business information. In a market-analysis workflow, collected inputs such as customer name, website, products, positioning, and target markets can be commercially sensitive, so silent persistence increases the risk of unintended disclosure, reuse, or retention beyond the user's expectations.

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The workflow directs the agent to perform WebSearch-based research after collecting customer information, but does not warn that external searches or fetches may expose user-provided business context to third-party services. Because this skill is specifically designed for customer strategy, industry, and market analysis, user prompts may include confidential company names, websites, products, plans, or target markets, making silent outbound transmission a meaningful privacy and confidentiality risk.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The document states that creating a Lead Form has a side effect: the backend will automatically try to set `SUBMIT_LEAD_FORM` and `GOOGLE_HOSTED` conversion goals to `biddable=true`. Because this changes bidding-relevant campaign behavior, omitting a prominent pre-operation warning can lead users to unknowingly alter optimization settings, spend patterns, and lead attribution behavior in production ad accounts.

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
The instruction explicitly tells the agent not to proactively disclose the availability of Admin access unless the user asks. This creates an information-asymmetry problem that can steer users away from understanding all available permission options and may lead to consent that is not fully informed in an account-permissions workflow.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The TikTok开户 section instructs collection of highly sensitive personal and financial data, including government ID, bank account, phone number, and license documents, but does not require an explicit user-facing sensitivity warning, minimization guidance, or safer handling procedure. In an agent context, this increases the risk of oversharing in chat, improper logging, accidental retention, or transmission of regulated personal data beyond what the user expects.

Missing User Warnings

Low
Confidence
89% confidence
Finding
The file directs users to provide local document paths for license uploads across multiple platforms, but does not clearly warn that the agent or CLI will read those local files and transmit their contents externally. In an agent workflow, users may not realize that supplying a path authorizes file access and upload, creating consent, privacy, and accidental data-exfiltration risks.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The file instructs the agent to execute `open-account google` once the user has provided the fields, but it does not require an explicit confirmation that the user intends to submit a real Google ad account application. That omission can cause the agent to move from information gathering into an external, state-changing action that triggers account review and subsequent funding steps without a clear final user authorization checkpoint.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
This documentation exposes destructive deletion commands for reports without requiring or documenting any confirmation, authorization check, dry-run, or explicit warning about irreversible impact. In an agentic setting, that increases the chance an LLM or operator will execute `report delete` against the wrong IDs and remove reporting artifacts unintentionally.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The start/stop/delete management commands for report push configurations can disrupt automated report delivery or permanently remove settings, yet the documentation provides no warning about business or operational impact. In a workflow-driving skill, an agent may invoke these commands directly, causing silent interruption of reporting or loss of configuration.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
This documentation instructs users and agents to place long-lived authentication material in `~/.siluzan/config.json` or environment variables and even demonstrates commands containing secrets inline. In an agent/automation context, that increases the chance of credential exposure through shell history, logs, screenshots, process listings, shared home directories, or accidental exfiltration by other tools.

Missing User Warnings

Medium
Confidence
85% confidence
Finding
The document exposes live mutation commands for ad batch records, including update and publish, without any warning that these actions can change campaign configuration or activate spend-bearing ads. In an agent setting, this increases the chance of unsafe execution from ambiguous prompts or automation flows, especially because publish is operationally irreversible once changes propagate to advertising systems.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The document instructs the agent to delete a live ad campaign in a partial-failure branch without requiring a fresh, explicit user-facing warning at the point of deletion. In an agentic workflow handling real advertising accounts, this can cause destructive account changes based on internal recovery logic rather than an informed user decision.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.