Back to skill

Security audit

success-referral-generation

Security checks for vulnerabilities and agentic risk

Overview

This is a guidance-only referral playbook for China-focused B2B sales teams, with privacy and compliance caveats that users should still apply carefully.

Install this if you want a China-focused B2B referral workflow. Before using it with real customer data, confirm consent for any chat screenshots or referred-contact details, follow your company's CRM/privacy retention rules, and avoid using the playbook as-is for non-China markets without adapting the channels and legal assumptions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file explicitly states that all scripts are rewritten for China-specific channels such as WeChat, WeCom, and group chats, and says they do not rely on overseas email. This hard-codes a locale and communication-channel assumption into the skill without any visible user opt-in or branching logic, which can cause the agent to generate inappropriate, noncompliant, or unusable guidance for users in other regions or regulated environments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file instructs users on potentially sensitive outreach behaviors such as creating three-party chats, referencing introducers, and contacting referred individuals. Although L39 mentions compliance and consent in one subsection, the overall skill description lacks an explicit warning section that clearly discloses privacy, consent, and relationship risks before users apply the playbook.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill explicitly recommends using identifiable customer communications such as WeChat or enterprise chat screenshots with avatars and timestamps as evidence, but only limits external reuse and does not address collection minimization, storage controls, retention, or consent for internal handling. This creates a real privacy and data-governance risk because staff may capture, retain, and circulate personal data and customer statements in ways that violate internal policy, confidentiality expectations, or applicable privacy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

该技能文档全文以中文呈现,且未见任何允许用户选择其他语言/区域设置的说明,也未说明这是仅面向特定中文场景用户的语言要求。按照自然语言政策要求,强制单一语言而无用户选择可能构成语言/locale 约束问题。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.