Back to skill

Security audit

Paid Waitlist Page

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed SettleMesh workflow for deploying hosted paid waitlist pages, with meaningful but purpose-aligned authentication, hosting, database, and optional payment behavior.

Install this only if you want an agent to use SettleMesh to deploy a real hosted page with a managed database and optional payment gate. Review any deploy, payment, or credit-spending confirmation carefully, and avoid invoking it for simple static mockups or copy-only landing pages.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill description contains broad trigger phrases such as "waitlist page," "landing page," "coming-soon page," and "collect emails and charge for early access," which can match many ordinary user requests and cause the agent to invoke this skill in contexts where the user did not intend deployment, database persistence, or payment setup. In this skill, overbroad matching is more dangerous because execution can lead to authenticated network actions, hosted deployment, persistent data collection, and potentially spend-gated payment flows.

Static analysis

No suspicious patterns detected.