Back to skill

Security audit

clinch-progression-strategy

Security checks for vulnerabilities and agentic risk

Overview

This is a China-focused sales planning skill with no executable code, but users should handle customer intelligence and saved deal plans carefully.

Install only if you want a China-focused B2B sales progression workflow. Do not use it as a general global sales playbook without adapting sources and procurement assumptions, and review any generated progression-strategy.md before storing or sharing it because it may contain customer names, stakeholders, budgets, and internal deal assessments.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (6)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill explicitly directs use of China-specific data sources and bans common global sources without establishing that the user, customer, or opportunity is actually China-scoped. That can cause the agent to apply the wrong jurisdiction, language, and sourcing policy to a user’s request, leading to inappropriate data handling, biased research coverage, or exclusion of relevant sources during decision support.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The title and the entire document are written in Chinese, and the content includes China-specific guidance, but there is no natural-language statement that this skill or reference is optional, localized by user choice, or restricted to a China-only use case. Under the language/locale policy criterion, this can be interpreted as enforcing a specific language/locale without explicit opt-in or justification in the file itself.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guidance explicitly recommends using semi-private social and recruiting sources such as WeChat Moments, industry groups, and hiring platforms to infer internal customer dynamics, personnel changes, and budget direction, but provides no privacy, consent, or compliance guardrails. In a sales-progression skill, this increases the chance that users will collect or act on personal or sensitive intelligence in ways that violate platform rules, internal policy, or privacy expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The template explicitly says each skill invocation should be written to disk, but it provides no requirement to notify the user, obtain consent, or limit what is stored. Because the template captures deal details, stakeholder identities, budgets, timelines, and internal assessments, silent persistence can create confidentiality, privacy, and data-retention risk if the output is stored in logs, shared workspaces, or insecure local files.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file contains user-facing instructional content exclusively in Chinese, and there is no indication that the skill is intended only for Chinese-speaking users or that language selection is optional. Under the policy rule, forcing a specific language without user opt-in can be a locale-policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

L76 states "禁用" for LinkedIn, Apollo, G2, and Capterra as a hard rule. This is a natural-language locale policy constraint that forces a China-specific data-source policy without framing it as context-dependent guidance, user choice, or a clearly scoped regional limitation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.