Back to skill

Security audit

上市策略工具专业版

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Markdown-only GTM analysis skill with broad but purpose-aligned read, write, and command permissions and no evidence of hidden or destructive behavior.

Install only if you are comfortable letting the agent read relevant GTM data, run local analysis commands, and write reports or exports. Use scoped advertising, CRM, or analytics tokens, avoid unnecessary customer or regulated data, and require explicit approval before delete, reset, or broad export actions.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill advertises read/exec/write capabilities plus create/modify/delete/save/export style operations without prominently warning that these actions may change files or execute commands on the host. In an agent environment, vague operational language combined with powerful tools can lead to unintended system-impacting actions, especially if the user believes the skill is only producing business analysis.

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The skill recommends integrating advertising, CRM, analytics APIs, and platform tokens but does not warn users that business metrics, customer, marketing, or competitive data may be transmitted to external systems. In a GTM/attribution context, that data can be commercially sensitive, so omission of privacy and data-handling guidance materially increases leakage risk.

Static analysis

No suspicious patterns detected.