Back to skill

Security audit

investor-update

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed drafting helper for investor updates and does not include code, persistence, sending, or hidden data movement.

Install only where you are comfortable letting the agent summarize the Slack, Gmail, analytics, or billing sources you explicitly provide or connect. Review the generated draft carefully before sending, especially revenue, burn, runway, customer, hiring, and fundraising details.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Intent-Code Divergence

Medium
Confidence
91% confidence
Finding
The README states the skill 'does not connect to any source,' but later says it pulls material from reachable Slack, Gmail, and analytics MCPs. This mismatch can cause users to grant or assume less data access than the skill actually uses, undermining informed consent and increasing the risk of unintended access to sensitive communications and business data.

Intent-Code Divergence

Low
Confidence
84% confidence
Finding
The README reassures users that the skill 'only reads the channels and threads you point it at,' while earlier text says it pulls from whatever is reachable in the session. That ambiguity can broaden perceived authorization boundaries and lead to overcollection from investor, finance, HR, or customer communications in a high-sensitivity context.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger list includes broad natural-language phrases such as "investor update" and "LP update" that could match ordinary conversation and cause the skill to activate when the user did not intend to invoke it. Because this skill is designed to read from reachable session data sources like Slack, Gmail, and analytics MCPs, unintended activation could expose or summarize sensitive business information in the wrong context.

Static analysis

No suspicious patterns detected.