Skip to content
Report library
Purpose / Other

Co Marketing Skill Security Audit

What the author says it does (original text)

When the user wants to find co-marketing partners, plan joint campaigns, or brainstorm partnership opportunities. Use when the user says 'co-marketing,' 'partner marketing,' 'joint campaign,' 'who should we partner with,' 'integration marketing,' 'cross-promotion,' 'collaborate with another company,' 'partnership ideas,' or 'co-brand.' For customer referral programs, see referrals. For launch-spec

Independent security check

Security risks found

Files checked
3
Risks found
3
Could it run dangerous commands?Looks for programs run straight after downloading, remote control of your computer, and hidden commands.No risks found
Could it expose your files or keys?Looks for uploads of files containing passwords or keys, and keys written directly in the code.Risks found: 2
Medium risk

Joint lead-generation plans may expose prospects’ personal data to a partner

Source references: 2
What we found

The Skill recommends gated content with split leads and asks the parties to define how leads are captured, shared, and followed up, but does not require contact consent, field and purpose limits, retention periods, or a check of applicable privacy rules.

Why this matters

If a user gives another company registrants’ names, email addresses, or sales status, contacts may receive unexpected marketing, and the user may breach privacy promises, contracts, or data-protection requirements.

The skill presents gated-content leads as splittable between partners and directs both parties to decide how leads are captured, shared, and followed up. If the shared-leads option is used, contact data could pass to another company; the text does not address consent, shared fields, purpose limits, or retention. A user can require clear privacy notice, legal basis, data minimization, and deletion terms.

SKILL.md:106In the instructionsOpen original file
| Format | Effort | Lead Sharing | Best For ||--------|--------|--------------|----------|| **Co-authored blog post** | Low | Shared byline, link exchange | Thought leadership, SEO || **Joint ebook/guide** | Medium | Gated, split leads | Lead gen, deeper topic || **Research report** | High | Gated, split leads | Authority, PR || **Guest newsletter swap** | Low | Each keeps own leads | Audience exposure || **Podcast guest exchange** | Low | Each keeps own leads | Relationship building |
Show 1 other places
SKILL.md:223In the instructionsOpen original file
### Simple Co-Marketing Agreement Outline1. **Campaign description**: What you're doing together2. **Responsibilities**: Who does what3. **Timeline**: Key dates and deadlines4. **Lead handling**: How leads are captured, shared, followed up5. **Promotion**: Minimum commitments from each side6. **Branding**: Logo usage, approval process7. **Costs**: Who pays for what (if any)8. **Metrics sharing**: What data you'll share post-campaign
Medium risk

Partner preparation and reporting may disclose sensitive commercial data

Source references: 4
What we found

The guide tells users to prepare audience size, traffic, and engagement figures and to share metrics in the agreement and after the campaign, without distinguishing aggregate from customer-level data or requiring confidentiality, access controls, or scope limits.

Why this matters

A user could reveal non-public growth metrics, channel performance, attributed revenue, or customer-level conversion details, weakening negotiating leverage and giving the partner or its staff unnecessary business intelligence.

The skill asks users to prepare audience size, traffic, engagement, and account-overlap data, and to put post-campaign metric sharing into the agreement. Although these can be aggregate figures, they may still reveal non-public performance or customer-overlap information; the text does not limit granularity, recipients, or confidentiality. Users can require minimum necessary aggregate metrics, access limits, confidentiality terms, and no customer-level disclosure.

SKILL.md:202In the instructionsOpen original file
### What to Prepare for the Call1. **Account overlap data** (if available via Crossbeam/Reveal)2. **2-3 specific campaign ideas** (not just "let's do something")3. **Your audience metrics** (list size, traffic, engagement)4. **Examples of past partnerships** (shows you can execute)5. **Clear ask** (what you want from them, what you'll provide)
Show 3 other places
SKILL.md:228In the instructionsOpen original file
3. **Timeline**: Key dates and deadlines4. **Lead handling**: How leads are captured, shared, followed up5. **Promotion**: Minimum commitments from each side6. **Branding**: Logo usage, approval process7. **Costs**: Who pays for what (if any)8. **Metrics sharing**: What data you'll share post-campaign
SKILL.md:240In the instructionsOpen original file
- Leads generated (total and per partner)- Lead quality (MQL/SQL conversion rate)- Revenue attributed- Audience growth (new subscribers, followers)- Content engagement (views, downloads, shares)
SKILL.md:275In the instructionsOpen original file
### Post-Campaign- [ ] Share metrics with partner- [ ] Debrief on what worked/didn't- [ ] Discuss future collaboration opportunities
Could it delete files or keep running?Looks for broad file deletion, disk overwrites, and programs set to start automatically.No risks found
Could it bypass safety checks?Looks for skipped website security checks, excessive file access, or actions that skip your approval.No risks found
Could it mislead the AI or hide text?Checks the skill instructions for requests to ignore you, influence the report, or hide text in invisible characters.No risks found
Could it change links or payment recipients without asking?Looks for forced referral or payment changes combined with instructions to hide the change.Risks found: 1
Medium risk

“Permissionless” brand-halo advice may imply an unauthorized association

Source references: 1
What we found

The reference explicitly recommends building assets around famous brands to ride their brand halo and says no signed partnership, permission, or contract is needed. It does not require checks for trademarks, brand rules, implied endorsement, or factual accuracy.

Why this matters

Published templates, landing pages, or promotions could lead customers to believe a partnership, approval, or authorization exists, resulting in complaints, takedown demands, trademark disputes, or reputational harm.

The reference actively recommends creating assets around larger brands without permission or a contract to gain brand halo. It is strategy, not automatic execution, and is not inherently unlawful; however, names, logos, or presentation could imply a partnership or endorsement that does not exist, creating trademark and reputational risk. Users can require brand-guideline review, factual verification, and a clear non-affiliation disclosure.

references/partnership-types.md:73In the instructionsOpen original file
Joint campaigns with a non-competing peer who shares your audience. Covered in depth in the main SKILL.md (campaign types, partner scoring, agreements). Two ideas from the chapter worth calling out:**Permissionless co-marketing (Notion's coined move) — the single most actionable idea in the chapter.** You don't need a signed partnership to ride a bigger brand. Notion built and published templates *for* Airbnb, Amazon, and Tesla — no permission, no contract — capturing search demand and brand halo from companies far larger than itself. **Build assets around brands your audience already loves; let the association do the work.**

Inside this skill

8 instruction sections

This Skill is a co-marketing strategy guide for SaaS companies. It first reads a project product-marketing context file, then helps select partners, brainstorm joint campaigns, draft outreach, and plan partnership terms.

View source
SKILL.md:8In the instructionsOpen original file
You are a co-marketing strategist who helps SaaS companies identify ideal partners and brainstorm high-impact joint campaigns.
SKILL.md:12In the instructionsOpen original file
**Check for product marketing context first:**If `.agents/product-marketing.md` exists (or `.claude/product-marketing.md`, or the legacy `product-marketing-context.md` filename, in older setups), read it before asking questions. Use that context and only ask for information not already covered or specific to this task.

It divides partnerships into integrations, resellers, affiliates, co-marketing, and app marketplaces, and scores candidates on audience fit, brand alignment, reciprocity, execution difficulty, and related factors.

View source
SKILL.md:45In the instructionsOpen original file
Rate potential partners (1-5) on:| Criteria | What to Evaluate ||----------|------------------|| **Audience fit** | How closely does their audience match your ICP? || **Audience size** | Do they have reach worth partnering for? || **Brand alignment** | Would you be proud to be associated? || **Engagement quality** | Do they have an active, engaged audience? || **Reciprocity potential** | Can you offer them equal value? || **Ease of execution** | Do they have a partnerships team? History of co-marketing? |
SKILL.md:86In the instructionsOpen original file
| Type | What it is | Primary payoff ||------|-----------|----------------|| **Integrations** | Your product connects to another's (native, Zapier, API-first, embedded) | Retention, expansion, marketplace discovery || **Reseller** | Partners sell your product + services | Distribution + services revenue || **Affiliate** | Promoters earn commission on referrals | Low-risk, pay-for-performance reach || **Co-marketing** | Joint content/campaigns with a peer | Borrowed audience, brand halo || **App Store / Marketplace** | List inside a platform's ecosystem | Built-in distribution, effective CAC |

The supplied files contain instructions, reference material, and evaluation cases only; the visible content contains no scripts, installation commands, credential requests, or direction to send outreach automatically.

View source
SKILL.md:184In the instructionsOpen original file
### Cold Outreach Template```Subject: [Your Company] + [Their Company] co-marketing ideaHey [Name],I'm [Role] at [Your Company]. We [one-line description].I noticed we share a lot of the same audience—[specific observation about overlap].I have an idea for [specific campaign type] that could work well for both of us: [one-sentence pitch].Would you be open to a quick call to explore?[Your name]```
Start here · InstructionsSKILL.md
co-marketing
Lines connect the instruction file to its sections, not an observed execution order. Select a section to read the source. 5 more sections are available in the original file.

File reference map

References: 2
Files making referencesReferenced content
Lines show actual file references, not execution order. Select a node to highlight its connections and inspect the files and source locations. Dashed lines include files that still need locating.
Files and check records3 files

Coverage and gaps

Content covered in each file

These are the source ranges included in this check, not a guarantee that every issue has been resolved.

  • SKILL.mdFull text included
  • references/partnership-types.mdFull text included
  • evals/evals.jsonFull text included

This report is for the version above. We read the available code and instructions without running the skill or checking extra packages it installs. This is not a promise of safety: a different version or setup may behave differently.

  • SKILL.mdInstructions
  • evals/evals.jsonSupporting file
  • references/partnership-types.mdSupporting file
Lines read
511
File checksum (to compare versions)
59aabd1d339f98e3d540c7efa4b892396276d54a70c8d69199285e5d4340506a