Back to skill

Security audit

Email & Newsletter

Security checks across malware telemetry and agentic risk

Overview

This skill provides newsletter strategy and drafting guidance with clear limits against sending email, fabricating metrics, or using non-consensual lists.

Before installing, understand that the skill may help draft newsletter content and social posts and may rely on brand voice, content pillars, ESP metrics, and GA4 summaries you provide. Keep final review, email sending, list management, consent, unsubscribe compliance, and public social publishing under human control.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Low
Confidence
28% confidence
Finding
SQP-3 only applies to natural-language policy violations such as forcing a specific language or locale. This file is largely advisory content and does not explicitly require a language, so the concern is weak; however, the platform framing is somewhat locale-specific and lacks any note about alternatives for other regions or languages.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.