Back to skill

Security audit

success-churn-recovery

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed China-focused B2B customer win-back playbook with no executable code, persistence, or hidden system behavior.

Before installing, treat this as a China-market sales playbook. Use only contact data and customer records your organization is authorized to use, avoid informal personal-data collection or broad circulation of phone/WeChat details, and keep outreach within CRM, compliance, and local privacy rules.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description, title, instructions, and examples are written entirely in Chinese, and the workflow assumes Chinese-language use throughout. This creates a language/locale constraint without any opt-in, alternative language option, or explicit justification that the skill is restricted to Chinese-speaking users only.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown guidance repeatedly states that specific China-market channels and norms are the required approach, such as prioritizing WeChat/enterprise WeChat over email and asserting that email is effectively unusable. Under the policy, forcing a specific language/locale or region-specific operating model without user choice or explicit scope can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file contains operational instructions only in Chinese, and there is no natural-language indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking audience. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The title and introductory text are entirely in Chinese and the playbook is framed specifically around Chinese business practices, but there is no statement that the skill is China-specific or that users can opt into another language/locale. This creates a natural-language policy issue because the skill implicitly enforces a specific language and locale context without user choice.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest says this skill should help sales/CS assess rescue-vs-knife motives, identify Champion political situation, design a D-X backward plan, include a 30-day joint validation Plan B, and set 3 stop-loss signals for win-back of already-lost customers. This file instead presents a generic 'save plays' library explicitly derived from a renewal-predictor template, and does not implement or document those core churn-recovery-specific elements.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The playbook instructs users to identify and reach decision-makers through social graphs, intermediaries, and workplace channels without any privacy, lawful-basis, or consent guardrails. In a customer-success context, this normalizes off-book collection and use of personal relationship data, creating privacy-compliance, harassment, and reputational risk, especially where employees may over-collect or misuse personal information.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest limits the skill to already-lost customers and explicitly excludes churn prediction and renewal prevention. Play 8 ('主动健康检查') and Play 9 ('功能采用冲刺') are preventive customer-success interventions for at-risk or low-adoption accounts, which belong to pre-churn/renewal management rather than post-loss recovery.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The one-page template encourages sharing named contacts, phone numbers, and WeChat identifiers without any instruction on data minimization, authorization, or secure handling. In practice, this can lead to unnecessary distribution of personal contact details in documents circulated beyond the intended audience, increasing privacy and social-engineering exposure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file uses Chinese throughout for headings, instructions, examples, and workflow descriptions, which effectively forces a single language on users. Under the policy, language constraints should either provide user opt-in/choice or be clearly documented as region-specific and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file is written entirely in Chinese and explicitly scoped to '中国 B2B 流失', but it does not offer any language or locale choice or state that the skill is intentionally region-specific for users who opt into that context. Under the policy for natural-language violations, a forced language/locale constraint without user opt-in can be flagged.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.