Back to skill

Security audit

DeepContent

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a real DeepContent marketing integration, but it needs Review because broad triggers, external account data flows, and persistent preference memory are under-scoped.

Install only if you want your agent to use a DeepContent API key, send URLs and brand/account context to DeepContent, and remember editing preferences across future interactions. Review generated posts, brand confirmations, and team invites before approval, and avoid using the skill for URLs or business data you do not want processed by that service.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill’s trigger scope is very broad, including generic phrases like 'generate content' and effectively any URL. That increases the chance of unintended invocation, which can cause users to send URLs and account-context actions to the external DeepContent service without clear intent or informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill directs the agent to send user-supplied URLs, generated content context, and authenticated account data to a remote API, but the description does not clearly warn users about that data flow. This reduces informed consent and can expose browsing targets, brand data, org identifiers, and workflow metadata to an external service unexpectedly.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly instructs the agent to retain and profile user editing behavior across interactions, including preferences and repeated changes. Persistent behavioral profiling without a clear consent, retention policy, or minimization controls creates privacy risk and can accumulate sensitive preference data beyond what is necessary for the immediate task.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The instruction "Ask which platforms (linkedin, x, reddit)" is embedded in an otherwise English-only skill description and there is no indication that users may choose another language or locale for the interaction or generated content. This creates a mild language-policy concern because the skill appears to assume a single language by default without opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.