Back to skill

Security audit

copywriting

Security checks for vulnerabilities and agentic risk

Overview

This is a copywriting guidance skill with no executable code, credentials, persistence, or high-impact system access.

Before installing, note that this skill may be invoked by broad copywriting terms and should be used for marketing text. Users should verify any claims, scarcity statements, testimonials, prices, or performance numbers before publishing generated copy.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The description says to trigger on phrases like "headline" and "copywriting," which are broad terms that can appear in ordinary discussion without a clear intent to invoke this skill. The file also does not provide exclusion conditions or negative examples to narrow when those triggers should and should not activate.

Autonomous Decision Making

Medium
Category
Excessive Agency
Content
**CTA placement:**
- Above the fold (so they don't have to scroll to act)
- After explaining value (don't ask before you've sold them)
- Multiple times on long pages (after each value section)

---
Confidence
80% confidence
Finding
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Static analysis

No suspicious patterns detected.