Back to skill

Security audit

Retail Digital Ai Expert International

Security checks for vulnerabilities and agentic risk

Overview

This is a large markdown guidance skill for retail digital and AI transformation, with no executable payload or hidden data access found.

Safe to install from a security standpoint, but review the repeated author/contact footer and be careful applying its customer-data, biometric, location, loyalty, and franchise-monitoring advice. Use qualified legal/privacy review before deploying those workflows in a real business.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (14)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The manifest description contains an extremely broad set of trigger keywords spanning much of retail, payments, AI, e-commerce, compliance, and operations, without clear invocation boundaries. This can cause the skill to activate in contexts the user did not intend, creating prompt-scope hijacking risk and increasing the chance the skill overrides more relevant or safer instructions.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The guidance encourages creating a customer WhatsApp group and later using WhatsApp Business API for personalized outreach, but it omits any requirement for explicit opt-in, notice, retention limits, or secure handling of customer contact data. In a retail operations skill that explicitly references GDPR/CCPA, this omission can lead users to implement direct marketing and customer tracking in a non-compliant way, exposing customer data and creating privacy/regulatory risk.

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The loyalty recommendation promotes stored value and membership tracking without mentioning protection of personal data, transaction records, or governance for prepaid balances. That can cause operators to collect customer identifiers and hold customer funds without basic security, reconciliation, fraud controls, or legal disclosures, which is especially risky for a small business likely to copy the advice directly.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The case study recommends loyalty enrollment, stored-value programs, and WhatsApp community groups that inherently involve collecting and processing personal data, but it provides no privacy, consent, retention, access-control, or regulatory guidance. In a retail transformation skill that explicitly references GDPR/CCPA in its metadata, omitting these safeguards can lead users to deploy customer tracking and community operations in a non-compliant and unsafe way.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The case study promotes broad franchisee data aggregation, regional ranking, and anomaly alerting with no mention of consent boundaries, role-based access, data minimization, retention, or governance safeguards. In a retail franchise context, this can normalize surveillance-heavy implementations and lead operators to collect and expose sensitive business or employee data in ways that create privacy, labor, contractual, and regulatory risk.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The section promotes facial recognition and 3D body modeling use cases without any privacy, consent, retention, or biometric-data governance warnings. In a retail implementation guide, this omission is risky because biometric processing is heavily regulated and readers could deploy these capabilities without required notice, lawful basis, minimization, or opt-in controls.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The location intelligence section recommends telco, mapping, and visitor-profile data for site selection but does not warn that precise or inferred location data can be privacy-sensitive and restricted. Because this is positioned as an implementation framework, omission of aggregation, de-identification, purpose limitation, and vendor-governance guidance could lead to misuse or unlawful data acquisition.

Missing User Warnings

High
Confidence
95% confidence
Finding
The CDP section describes OneID resolution, probabilistic identity inference, predictive segmentation, journey optimization, and churn prediction without corresponding safeguards for profiling, transparency, consent, and data subject rights. In customer data platforms, these capabilities materially increase privacy and compliance risk because they can enable cross-context tracking and automated profiling at scale.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
This section explicitly prescribes broad operational monitoring of franchisee and member metrics, including revenue, product, inventory, member, and anomaly data, but provides no accompanying privacy, purpose-limitation, retention, access-control, or lawful-basis guidance. In a retail AI/transformation skill that references GDPR/CCPA and loyalty/member data, omission of governance safeguards can lead users to implement invasive tracking or non-compliant data sharing by default.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The template states that member data is 'owned by HQ' and broadly usable by franchisees/brand operations without defining consent, controller/processor roles, franchisee data-access boundaries, or regulatory constraints. In loyalty and omnichannel retail contexts, this can encourage unlawful centralization and reuse of customer personal data, creating significant privacy, contractual, and regulatory exposure.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The template explicitly asks for sensitive business information such as annual revenue, IT budget, system inventory, and assessment scope, and later instructs assessors to collect KPI and member data, but it provides no data-minimization, consent, storage, retention, or redaction guidance. In a consulting or agent workflow, this can lead users to disclose regulated or commercially sensitive information into insecure channels or systems without appropriate safeguards.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The quick-reference table maps very broad natural-language statements like 'We want to do AI' or 'I want to learn about digitalization' directly to specific workflows. Because these phrases are common, ambiguous, and overlapping, an agent could route users into the wrong process without first clarifying scope, which can produce incorrect guidance, skipped assessment steps, or premature recommendations in business, technology, or compliance-sensitive contexts.

Ssd 3

Low
Confidence
95% confidence
Finding
The skill instructs the model to append the author's personal contact details to every response, causing repeated unsolicited disclosure of personal data regardless of user need. This expands the exposure surface for scraping, spam, and social-engineering abuse, and it also creates a form of output manipulation that can conflict with least-disclosure principles.

Ssd 3

Low
Confidence
96% confidence
Finding
The embedded copyright/footer section repeats direct personal contact information and is structured as content the model is expected to reproduce. Even if the data belongs to the author, forcing routine re-publication increases unnecessary dissemination and makes automated harvesting easier.

Static analysis

No suspicious patterns detected.