Back to skill

Security audit

Yunlv Email Writer

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed business-email drafting aid with some quality and privacy wording caveats, but no evidence of hidden access, exfiltration, or unsafe automatic actions.

Install only if you are comfortable providing business email context to your agent environment. Review generated outreach for accuracy, recipient consent, unsubscribe or opt-out needs, and regional marketing rules; also verify non-English output before sending because some language selections may produce English drafts for later translation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The trigger phrase at this line is broad enough to activate during ordinary business discussion, not just when the user explicitly wants this email-writing skill. Over-broad activation can cause unintended context loading and unnecessary exposure of user-provided business content to the skill workflow.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This trigger overlaps with common business terminology and may cause the skill to run when users are merely discussing quotations rather than asking to write a quotation email. Such accidental invocation increases the chance of irrelevant prompt injection surface and inadvertent handling of commercial data.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

A generic English trigger like this lacks enough specificity for reliable scoping and can match many unrelated conversations. In skill-based systems, weak scoping raises the risk of accidental activation, unnecessary prompt expansion, and avoidable data exposure.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill claims that generated email content is processed and retained only locally, but the artifact is an AI skill prompt and does not itself guarantee local-only execution or storage. This can mislead users into providing sensitive customer, pricing, or business data under false privacy assumptions, creating confidentiality and compliance risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file presents the skill entirely in Chinese, starting with the title and section headings, while the policy requires flagging language or locale constraints that force a specific language without user opt-in. There is no note that the templates are intended only for Chinese-speaking users or any option to select another language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The guide presents region- and language-specific communication rules as prescriptive defaults rather than optional, contextual suggestions. In an email-writing skill, this can cause the agent to apply cultural stereotypes or locale-specific behavior without explicit user consent, leading to biased, inappropriate, or misleading business communications.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest explicitly describes professional email writing in multiple languages, including use cases for multilingual business emails. In code, inquiry replies for Arabic, Spanish, and Russian do not generate those languages at all; they fall back to English and prepend a note saying it should be translated later. The same pattern appears in other generators, so the implemented behavior is narrower than the advertised multilingual capability.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file-level description claims support for CN/EN/AR/ES/RU, but for unsupported template branches the generator prepends a note and produces English content instead. This effectively forces English output without user opt-in, which is a natural-language locale policy concern because users selecting ar/es/ru do not actually receive content in their chosen language.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest and module docs present this as a generator for distinct foreign-trade email categories, but order_confirmation is handled by gen_inquiry_reply and after_sales is handled by gen_follow_up. That means the produced content semantics do not match the claimed email type, creating a mismatch between declared behavior and actual output.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
62% confidence
Finding

规则要求识别自然语言层面的语言/地区政策问题。该文件以中文作为默认说明语言,且未声明这是面向特定中文用户群或提供语言选择,可能与要求用户可选择语言/locale 的组织政策不一致。

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The template promotes a structured multi-step follow-up sequence, including repeated contact and urgency cues such as special offers and final reminders, without any guidance on consent, unsubscribe options, frequency limits, or applicable anti-spam/privacy rules. In an email-writing skill for B2B outreach, this can encourage users to generate borderline-harassing or non-compliant campaigns that create legal, reputational, or trust risks.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.