Back to skill

Security audit

上市策略工具

Security checks for vulnerabilities and agentic risk

Overview

This GTM planning skill mostly contains strategy templates, but it asks for command/write-style authority and advertises itself for coding and deployment tasks that do not match its purpose.

Review before installing. The GTM templates themselves are ordinary, but the skill should be narrowed to marketing-strategy tasks and should not request exec or broad write-style authority unless the publisher documents exact safe uses, destinations, and confirmation steps.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
The manifest and description materially mismatch the actual skill purpose: a GTM strategy generator is presented as suitable for code generation, debugging, and deployment workflows. This broadens where the skill may be invoked and can cause an agent to grant or use capabilities in inappropriate contexts, increasing the chance of unsafe execution paths or misuse of attached tools.

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The body claims generic create/query/modify/delete plus export/save/convert operations that are not justified by the documented GTM use case. Overstated operational scope can mislead an agent into treating the skill as a general-purpose workflow tool, which increases the chance of unintended data manipulation or file operations.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The skill declares exec capability even though it is documented as a markdown-based GTM planning tool with no legitimate need for shell execution. Unnecessary command execution materially expands the attack surface, because an invoked agent may execute local commands in response to ambiguous instructions or future prompt manipulation.

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
The documented tool set includes write access despite the skill being framed as content generation rather than file modification. Unneeded write capability enables unauthorized or accidental persistence of outputs, overwriting files, or planting artifacts in the workspace.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger language is overly broad and mismatched to the skill’s GTM purpose, explicitly telling agents to use it for code generation, programming assistance, testing, and deployment. Over-broad activation can cause the wrong skill to be selected in sensitive technical contexts, where its unnecessary exec/write permissions become much more dangerous.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The activation condition is ambiguous because it does not clearly separate supported GTM usage from unsupported tasks and repeats mismatched technical-workflow language. Ambiguous routing increases the probability of unintended invocation and misuse of attached tools in contexts unrelated to marketing planning.

Static analysis

No suspicious patterns detected.