Skip to content
Report library
Purpose / Other

Community Marketing Skill Security Audit

What the author says it does (original text)

Build and leverage online communities to drive product growth and brand loyalty. Use when the user wants to create a community strategy, grow a Discord or Slack community, manage a forum or subreddit, build brand advocates, increase word-of-mouth, drive community-led growth, engage users post-signup, or turn customers into evangelists. Trigger phrases: \"build a community,\" \"community strategy,\

Independent security check

Security risks found

Files checked
3
Risks found
4
Could it run dangerous commands?Looks for programs run straight after downloading, remote control of your computer, and hidden commands.No risks found
Could it expose your files or keys?Looks for uploads of files containing passwords or keys, and keys written directly in the code.Risks found: 1
Medium risk

Confidential marketing context may be carried into shareable strategy output

Source references: 3
What we found

The Skill automatically reads product-marketing context and uses it to produce strategy documents, welcome messages, outreach templates, and audit reports, but it provides no rule to filter customer information, unreleased plans, internal metrics, or other confidential material.

Why this matters

If the result is sent to community members, outside advisers, or public channels, sensitive business or personal information previously confined to the local marketing file could be disclosed unintentionally.

What this evidence establishes

The skill reads marketing context and can produce several documents or templates, but the source does not require verbatim copying, external transmission, or public posting. Whether confidential data appears in an output depends on the file contents, the request, and how the result is later shared, so the evidence is insufficient to establish the claimed disclosure. Users can ask for sensitive-field exclusions and confirmation before outreach or publication.

This assessment concerns the code and conditions shown, not proof that harm has occurred.
SKILL.md:14In the instructionsOpen original file
**Check for product marketing context first:**If `.agents/product-marketing.md` exists (or `.claude/product-marketing.md`, or the legacy `product-marketing-context.md` filename, in older setups), read it before asking questions. Use that context and only ask for information not already covered.
Show 2 other places
SKILL.md:148In the instructionsOpen original file
- **Community Strategy Doc** — Platform choice, identity definition, core loop, 90-day launch plan- **Channel Architecture** — Recommended channels/categories with purpose and posting guidelines for each- **New Member Journey** — Welcome sequence: pinned post, DM template, first-week prompts- **Community Ritual Calendar** — Weekly/monthly recurring events and threads- **Ambassador Program Brief** — Criteria, benefits, outreach template, tracking plan- **Health Audit Report** — Current metrics, diagnosis, top 3 priorities to fix
SKILL.md:144In the instructionsOpen original file
## Output FormatsDepending on what the user needs, produce one of:- **Community Strategy Doc** — Platform choice, identity definition, core loop, 90-day launch plan- **Channel Architecture** — Recommended channels/categories with purpose and posting guidelines for each- **New Member Journey** — Welcome sequence: pinned post, DM template, first-week prompts- **Community Ritual Calendar** — Weekly/monthly recurring events and threads- **Ambassador Program Brief** — Criteria, benefits, outreach template, tracking plan- **Health Audit Report** — Current metrics, diagnosis, top 3 priorities to fix
Could it delete files or keep running?Looks for broad file deletion, disk overwrites, and programs set to start automatically.No risks found
Could it bypass safety checks?Looks for skipped website security checks, excessive file access, or actions that skip your approval.Risks found: 1
Medium risk

Moderator access is suggested based on activity without security review or least privilege

Source references: 1
What we found

The Skill suggests giving moderator roles to power users but does not call for identity verification, scoped permissions, conflict review, audit logs, probation, or revocation procedures. Community activity alone does not establish that a person or account is suitable for administrative access.

Why this matters

If adopted directly, a compromised account or unsuitable member could delete content, access restricted channels, ban users, or impersonate official staff. The exact impact depends on the platform's moderator permissions.

The skill explicitly suggests identifying power users from activity and potentially granting moderator roles, which can confer real control over a community. The source does not pair this with identity checks, scoped permissions, probation, logging, or revocation. If implemented directly, a compromised or unsuitable account could affect content, restricted areas, or members. Users can require least privilege, human review, time-limited trials, and auditable revocation.

SKILL.md:82In the instructionsOpen original file
4. **Run recurring community rituals** — Weekly threads (e.g., "What are you working on?"), monthly AMAs, seasonal challenges. Rituals create habit.5. **Identify and invest in power users** — 1% of members generate 90% of value. Give them recognition, early access, moderator roles, or direct product input.
Could it mislead the AI or hide text?Checks the skill instructions for requests to ignore you, influence the report, or hide text in invisible characters.Risks found: 1
Medium risk

Local marketing files are trusted as instruction context, enabling indirect prompt injection

Source references: 1
What we found

The Skill tells the agent to read a product-marketing file and “use that context,” without requiring it to treat the content as untrusted data or ignore embedded operational instructions. A file contaminated through a template, sync process, or third party could contain instructions disguised as marketing facts.

Why this matters

Malicious content could divert the agent from the user's request, solicit additional information, or induce unauthorized follow-up actions. The available impact depends on the permissions of the agent running the Skill.

What this evidence establishes

The skill does require the agent to read and use a local marketing file, but the visible source does not tell it to execute commands found there, nor show that third parties can write the file. Indirect prompt injection is therefore conditional on how the agent separates data from instructions and who can modify these files. Users can ask the author to treat file contents strictly as data and restrict lookup to the intended project directory.

This assessment concerns the code and conditions shown, not proof that harm has occurred.
SKILL.md:14In the instructionsOpen original file
**Check for product marketing context first:**If `.agents/product-marketing.md` exists (or `.claude/product-marketing.md`, or the legacy `product-marketing-context.md` filename, in older setups), read it before asking questions. Use that context and only ask for information not already covered.
Could it change links or payment recipients without asking?Looks for forced referral or payment changes combined with instructions to hide the change.Risks found: 1
Medium risk

Revenue-sharing and referral tracking are suggested without commercial or disclosure controls

Source references: 1
What we found

The Skill recommends revenue sharing, referral links, and signup tracking without requiring written eligibility rules, attribution windows, payment approval, fraud detection, privacy notice, or disclosure of sponsored relationships.

Why this matters

Implementation could lead to disputed payouts, referral fraud, misleading endorsements, or tracking of individual behavior without adequate notice, affecting budgets, brand trust, and compliance decisions.

The skill explicitly recommends revenue sharing, referral links, and tracking traffic and signups. These actions affect payments, account attribution, and participant data. The visible instructions omit eligibility and payment terms, attribution disputes, fraud controls, privacy notice, and promotional disclosure. If launched as-is, this could enable incorrect payouts, referral abuse, or undisclosed commercial promotion. Users can require written terms, approval and anti-fraud controls, data minimization, and clear disclosure.

SKILL.md:88In the instructionsOpen original file
2. **Make the ask personal** — Don't send a generic form. Reach out 1:1 and explain why you chose them specifically.3. **Offer meaningful benefits** — Exclusive access, swag, revenue share, or public recognition — not just "early access to features."4. **Give them tools and content** — Referral links, shareable assets, key talking points, a private Slack channel.5. **Measure and iterate** — Track referral traffic, signups, and engagement driven by advocates. Double down on what works.

Inside this skill

8 instruction sections

The Skill mainly produces advisory materials such as community strategies, channel structures, onboarding journeys, event calendars, ambassador plans, and health audits. The provided content does not instruct the agent to execute scripts, install software, or submit account credentials.

View source
SKILL.md:146In the instructionsOpen original file
Depending on what the user needs, produce one of:- **Community Strategy Doc** — Platform choice, identity definition, core loop, 90-day launch plan- **Channel Architecture** — Recommended channels/categories with purpose and posting guidelines for each- **New Member Journey** — Welcome sequence: pinned post, DM template, first-week prompts- **Community Ritual Calendar** — Weekly/monthly recurring events and threads- **Ambassador Program Brief** — Criteria, benefits, outreach template, tracking plan- **Health Audit Report** — Current metrics, diagnosis, top 3 priorities to fix

Before responding, it looks for one of three predefined product-marketing files and uses its contents to reduce questions and tailor recommendations.

View source
SKILL.md:14In the instructionsOpen original file
**Check for product marketing context first:**If `.agents/product-marketing.md` exists (or `.claude/product-marketing.md`, or the legacy `product-marketing-context.md` filename, in older setups), read it before asking questions. Use that context and only ask for information not already covered.

Its growth playbooks include one-to-one outreach, referral links, revenue sharing, behavioral measurement, and potentially promoting active users to moderator roles.

View source
SKILL.md:82In the instructionsOpen original file
4. **Run recurring community rituals** — Weekly threads (e.g., "What are you working on?"), monthly AMAs, seasonal challenges. Rituals create habit.5. **Identify and invest in power users** — 1% of members generate 90% of value. Give them recognition, early access, moderator roles, or direct product input.
SKILL.md:86In the instructionsOpen original file
1. **Identify candidates** — Look for people who already recommend you unprompted. Check reviews, social mentions, community posts.2. **Make the ask personal** — Don't send a generic form. Reach out 1:1 and explain why you chose them specifically.3. **Offer meaningful benefits** — Exclusive access, swag, revenue share, or public recognition — not just "early access to features."4. **Give them tools and content** — Referral links, shareable assets, key talking points, a private Slack channel.5. **Measure and iterate** — Track referral traffic, signups, and engagement driven by advocates. Double down on what works.

`evals/evals.json` is test material containing expected outputs and assertions; for example, it describes recommendations the Skill should make rather than directly contacting users or changing community permissions.

View source
evals/evals.json:48In the instructionsOpen original file
      "id": 4,      "prompt": "Design an ambassador program for our community. We have about 5,000 members and a few that always help others. Want to give them more recognition.",      "expected_output": "Should apply the 'Building a Brand Ambassador / Advocate Program' playbook. Should recommend: identify candidates by looking at who already recommends and helps unprompted (check posts, replies, reviews, social mentions), make the ask personal 1:1 and explain why you chose them specifically, offer meaningful benefits beyond 'early access' (exclusive access, swag, revenue share, public recognition, direct product input), give them tools (referral links, shareable assets, talking points, private Slack channel), measure and iterate (track referral traffic, signups, engagement driven by advocates). Should cross-reference referrals skill for structured incentive programs. Should warn against generic forms and impersonal asks.",      "assertions": [        "Identifies candidates from existing helpful behavior",        "Recommends personal 1:1 ask",        "Suggests meaningful benefits beyond early access",        "Mentions tools/assets to enable advocates",        "Includes measurement plan",        "May cross-reference referrals skill"      ],
Start here · InstructionsSKILL.md
community-marketing
Lines connect the instruction file to its sections, not an observed execution order. Select a section to read the source. 1 more sections are available in the original file.

File reference map

References: 2
Files making referencesReferenced content
Lines show actual file references, not execution order. Select a node to highlight its connections and inspect the files and source locations. Dashed lines include files that still need locating.
Files and check records3 files

Coverage and gaps

Content covered in each file

These are the source ranges included in this check, not a guarantee that every issue has been resolved.

  • SKILL.mdFull text included
  • references/community-models.mdFull text included
  • evals/evals.jsonFull text included

This report is for the version above. We read the available code and instructions without running the skill or checking extra packages it installs. This is not a promise of safety: a different version or setup may behave differently.

  • SKILL.mdInstructions
  • evals/evals.jsonSupporting file
  • references/community-models.mdSupporting file
Lines read
344
File checksum (to compare versions)
e737c7c4888d97ad6f4b0cd2409e9571b372830bf0f150130813e03f36983318