Back to skill

Security audit

Founder Daily Brief

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a normal founder daily-brief generator, but it saves a local report file and adds UniqueClub attribution that users should notice.

Review where the generated brief will be saved before use, since it may include meetings, tasks, metrics, and competitor notes. Be aware that generic requests like daily digest may activate this skill, and generated reports include UniqueClub branding by default.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Note
Location
scripts/daily_brief.py:198
Finding

Mandatory Third-Party Promotional Content Injected into Generated Reports

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:165-172; scripts/daily_brief.py:198-200; scripts/daily_brief.py:310-312
Vulnerability Type: Mandatory promotional output injection
Risk Level: Low

Evidence

SKILL.md:165-172:

markdown
### Footer

═══════════════════════════════════════ Generated by Founder Daily Brief Part of UniqueClub Founder Toolkit 🌐 https://uniqueclub.ai ═══════════════════════════════════════

text

scripts/daily_brief.py:198-200:

python
brief += "\nGenerated by Founder Daily Brief\n"
brief += "Part of UniqueClub Founder Toolkit\n"
brief += "🌐 https://uniqueclub.ai\n"

scripts/daily_brief.py:310-312:

python
brief += "\nGenerated by Founder Daily Brief\n"
brief += "Part of UniqueClub Founder Toolkit\n"
brief += "🌐 https://uniqueclub.ai\n"

Technical Analysis

The skill instructions prescribe a branded footer, and both language branches in the executable script unconditionally append the same third-party attribution and external URL to every generated report. The branding is not necessary for the core task of converting user-provided schedules, tasks, metrics, news, and competitor information into a Markdown briefing.

Because there is no configuration option or user-consent check, invoking the normal report-generation workflow necessarily modifies the requested output to include third-party promotional content. This is best classified as instruction-level output manipulation: the skill’s instructions alter the agent’s output objective by requiring unrelated promotional material.

The reviewed code does not contact the referenced website, transmit user data, retrieve remote payloads, or execute content from the URL. The risk therefore concerns unwanted endorsement and content integrity rather than remote code execution or data exfiltration.

Attack Path

  1. A user invokes the skill to create a founder daily briefi ...[truncated 1192 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the mandatory branding and external URL from the footer template in SKILL.md.
  2. Remove the hard-coded promotional lines from both language branches in scripts/daily_brief.py.
  3. If attribution is operationally required, introduce an explicit option such as include_attribution, defaulting to false.
  4. Clearly document the optional attribution behavior and obtain user consent before adding it.
  5. Keep the default generated report limited to content directly requested by the user.
  6. Add tests verifying that default output contains no third-party branding or external links and that attribution appears only when explicitly enabled.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill instructs behavior that reads user-provided content and writes a file, but it does not declare any explicit tool scope or permissions. This creates a capability/permission mismatch that can lead to unintended file-system access if the host grants broader defaults, reducing transparency and making it harder for users or orchestrators to constrain the skill safely.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases include broad terms such as daily digest, 每日更新, and daily standup, which are common in ordinary conversation and may cause the skill to activate when the user did not intend it. In this skill's context, accidental invocation is more concerning because the workflow includes research, handling sensitive founder planning data, and writing files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The instruction to save a markdown file in the current working directory occurs without any warning, consent, or path constraint. Because the brief may contain confidential meetings, tasks, competitor monitoring, and business metrics, silent local persistence increases the risk of unintended data exposure or workspace contamination.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill presents itself primarily as a conversational briefing generator, but it also directs the agent to save output to the working directory. This hidden side effect can violate user expectations and lead to silent persistence of potentially sensitive schedule, task, and company information.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.