Back to skill

Security audit

营销文案大师

Security checks for vulnerabilities and agentic risk

Overview

This copywriting skill is mostly a Markdown guide, but it asks for and describes command, file, and API capabilities that are broader than its stated purpose.

Install only with restricted permissions: allow normal copy generation and, if needed, writes only to an explicit output folder. Avoid granting shell execution, broad local file access, network/API access, or callback use unless you separately review and approve each action.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Intent-Code Divergence

High
Confidence
95% confidence
Finding
The skill claims to be a pure Markdown, zero-dependency copywriting guide, yet its declared tools and later documentation imply broader operational capabilities. This mismatch is dangerous because users or agent frameworks may grant read/write/exec permissions under false assumptions, increasing the chance of unintended file access or command execution.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
A marketing copywriting skill has no clear need for command execution, API integration, file processing, or information retrieval beyond narrowly scoped content generation. Advertising these capabilities can cause over-privileged deployment and expands the attack surface for abuse such as local file manipulation, shell execution, or unintended external communication.

Intent-Code Divergence

High
Confidence
96% confidence
Finding
Troubleshooting guidance for API authentication, network failures, and command execution contradicts the earlier claim that the skill has no external dependencies. In context, this makes the skill more dangerous because it normalizes operational behaviors users would not expect from a pure copywriting template, potentially leading agents to invoke networked or executable actions with elevated trust.

Static analysis

No suspicious patterns detected.