Back to skill

Security audit

success-advocacy-management

Security checks for vulnerabilities and agentic risk

Overview

This skill is not executable malware, but it should go to Review because it contradicts its own stated scope and gives under-scoped instructions for customer outreach and sensitive customer evidence handling.

Review before installing. Remove or move the referral-introduction playbook to the proper referral skill, keep this skill limited to approved advocacy asset collection, require explicit customer authorization and approved company storage for screenshots/transcripts/customer metrics, and route any public collateral through marketing/legal review before use.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The document states that it does not handle referral generation, but the body repeatedly operationalizes referral requests and execution steps. This contradiction is dangerous because it can mislead reviewers and operators about the skill's true behavior, weakening policy enforcement and enabling inappropriate customer contact strategies.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly instructs the user to obtain introductions to peer CEOs, including sequencing, messaging, and follow-up, even though the manifest says referral-lead generation is out of scope. This creates a governance and compliance problem: users may use the wrong skill to generate prospecting activity under the cover of customer advocacy, bypassing intended controls and consent boundaries.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill tells the user to draft a thank-you letter, roundtable brochure, and case-study PDF, which goes beyond merely collecting raw customer advocacy assets. Producing outward-facing collateral without the proper workflow or approvals increases the risk of unauthorized publication, branding misuse, and accidental disclosure of customer information or statements.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill directs users to create a local folder for advocacy materials tied to a named customer, but provides no privacy, retention, access-control, or approved-storage guidance. In this context, those files may contain customer names, testimonials, business metrics, and approval artifacts, making casual local storage a realistic source of data leakage or mishandling.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

Lines L26-L32 state that testimony collection and outreach should use WeChat/WeCom instead of email or NPS for Chinese government-enterprise customers, as a default regional adaptation. This is a natural-language locale policy constraint without any user choice or opt-in mechanism, which fits the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guidance explicitly instructs users to mine customer praise from WeChat/enterprise chat, call transcripts, public posts, and acceptance records, but it does not provide a clear privacy and consent control section for collecting, storing, and reusing personal data. Although it notes that external use requires authorization and to hide other customers' information, the omission of explicit consent, recording/transcript legality, minimization, and retention rules creates a realistic risk of unauthorized collection or secondary use of customer statements and personal information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs users to capture and store customer group-chat screenshots and social-media signals as reusable assets, but it does not require explicit consent, data-minimization rules, retention limits, or safeguards for personal/confidential information. In a B2B customer-advocacy context, chats and social posts can contain employee names, third-party data, company-sensitive discussions, and platform-specific privacy expectations, so collecting them into an asset library creates avoidable privacy, confidentiality, and compliance risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The operational content of the skill is entirely in Chinese and includes Chinese-only suggested user-facing messages, but the file does not state that the skill is China-specific or require user opt-in to Chinese. Under the policy, forcing a specific language without user choice or documented justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

A language or locale policy issue applies to all file types when a skill forces a specific language without user opt-in. This file provides all operational guidance only in Chinese and contains no note offering alternative languages or explaining a justified locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file explicitly states that the qualification method is adapted for the China scenario. Under the policy rule for natural-language violations, locale-specific behavior should either be optional or clearly justified as region-specific compliance; here it is presented as the default with no user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The matching rules explicitly include '语言/规模' as a dimension, but the document does not offer any user language preference or explain a justified locale restriction. Under the policy rule, natural-language instructions that constrain language behavior without opt-in can be flagged when no choice is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.