Skip to content
Report library
Purpose / Writing

Content Strategy Skill Security Audit

What the author says it does (original text)

When the user wants to plan a content strategy, decide what content to create, or figure out what topics to cover. Also use when the user mentions "content strategy," "what should I write about," "content ideas," "blog strategy," "topic clusters," "content planning," "editorial calendar," "content marketing," "content roadmap," "what content should I create," "blog topics," "content pillars," or "

Independent security check

Security risks found

Files checked
4
Risks found
2
Could it run dangerous commands?Looks for programs run straight after downloading, remote control of your computer, and hidden commands.No risks found
Could it expose your files or keys?Looks for uploads of files containing passwords or keys, and keys written directly in the code.Risks found: 1
Medium risk

Broad triggers cause automatic reading of hidden product-marketing files

Source references: 3
What we found

The Skill instructs the agent to check and read several fixed-name local marketing files before asking questions. Because it also triggers for broad requests such as not knowing what to write, a user may not realize that an ordinary planning request accesses internal project context.

Why this matters

If the file contains non-public customer profiles, positioning, sales information, or business plans, that material can enter the model context and influence the response. It could be indirectly disclosed if the response is copied or shared. There is no instruction to upload or transmit the file automatically, so the risk depends on its contents and use of the response.

When broadly triggered by requests such as “content ideas,” the skill checks and reads several fixed-name marketing-context files before asking questions, even if the user did not explicitly provide them for that request. Those files may contain customer, positioning, or internal business information and will shape the recommendations. The evidence does not show upload or external transmission. A user can require confirmation and disclosure of the exact file before access, or run the skill only in a workspace without sensitive marketing material.

SKILL.md:14In the instructionsOpen original file
**Check for product marketing context first:**If `.agents/product-marketing.md` exists (or `.claude/product-marketing.md`, or the legacy `product-marketing-context.md` filename, in older setups), read it before asking questions. Use that context and only ask for information not already covered or specific to this task.
Show 2 other places
SKILL.md:2In the instructionsOpen original file
---name: content-strategydescription: When the user wants to plan a content strategy, decide what content to create, or figure out what topics to cover. Also use when the user mentions "content strategy," "what should I write about," "content ideas," "blog strategy," "topic clusters," "content planning," "editorial calendar," "content marketing," "content roadmap," "what content should I create," "blog topics," "content pillars," or "I don't know what to write." Use this whenever someone needs help deciding what content to produce, not just writing it. For writing individual pieces, see copywriting. For SEO-specific audits, see seo-audit. For social media content specifically, see social.metadata:
SKILL.md:3In the instructionsOpen original file
name: content-strategydescription: When the user wants to plan a content strategy, decide what content to create, or figure out what topics to cover. Also use when the user mentions "content strategy," "what should I write about," "content ideas," "blog strategy," "topic clusters," "content planning," "editorial calendar," "content marketing," "content roadmap," "what content should I create," "blog topics," "content pillars," or "I don't know what to write." Use this whenever someone needs help deciding what content to produce, not just writing it. For writing individual pieces, see copywriting. For SEO-specific audits, see seo-audit. For social media content specifically, see social.metadata:
Could it delete files or keep running?Looks for broad file deletion, disk overwrites, and programs set to start automatically.No risks found
Could it bypass safety checks?Looks for skipped website security checks, excessive file access, or actions that skip your approval.No risks found
Could it mislead the AI or hide text?Checks the skill instructions for requests to ignore you, influence the report, or hide text in invisible characters.No risks found
Could it change links or payment recipients without asking?Looks for forced referral or payment changes combined with instructions to hide the change.Risks found: 1
Low risk

Backlink budget guidance relies on format multipliers from one vendor study

Source references: 3
What we found

The Skill uses one vendor study of B2B SaaS sites to favor statistics roundup pages over original research or ultimate guides and supplies specific multipliers. It does label the study as directional, but the supplied material provides no original-report link or methodology for verification.

Why this matters

If treated as a general rule, the figures could steer content spending toward statistics pages even when the user's industry, site authority, or audience has different linking behavior.

The skill explicitly uses multipliers from a “single vendor study” to prioritize a statistics roundup, while acknowledging that the evidence is directional. No source link, sample details, or methodology is provided here, so a user allocating backlink budget could overestimate how well the precise figures apply to their market. It does not claim research or guides are worthless. A user can ask for a verifiable source and methodology and validate the recommendation against their own data or a small test before committing budget.

SKILL.md:129In the instructionsOpen original file
When the goal of a piece is backlinks specifically, format choice matters more than production effort. Foundation Inc.'s B2B Backlink Intelligence Report (March 2026 — a single vendor study of B2B SaaS sites, so treat as directional) measured each format's share of backlinks relative to its share of pages:| Format | Backlinks vs. page share ||---|---|| Statistics / data roundups | **4.25x** || Glossary / definition pages | 1.47x || Interactive tools / calculators (see **free-tools**) | 1.38x || How-to / tutorials | 1.36x || Original research / reports | 0.80x || Ultimate guides | 0.77x || Thought leadership | 0.74x || Templates / frameworks | 0.68x |
Show 2 other places
SKILL.md:142In the instructionsOpen original file
The counterintuitive read: **curating statistics earns ~5x the links of producing original research.** Writers link to whatever makes citation easiest — a maintained stat-roundup page is citation infrastructure, while original research often gets cited *via* the roundups that aggregate it. Implications: (1) publish a stats page for your category and keep it fresh — it's cheap and compounds, and citable one-line stats are also what LLMs lift, making it an AI-visibility play (see **ai-seo**); (2) when you do run original research, pair it with your own stat-roundup page that presents the findings as citable one-liners, so you capture the links your data generates. The formats at the bottom aren't dead — guides, templates, and thought leadership earn their keep on rankings, conversions, and brand. Judge each piece by the job it's for, and don't expect links from formats that don't earn them.
SKILL.md:131In the instructionsOpen original file
| Format | Backlinks vs. page share ||---|---|| Statistics / data roundups | **4.25x** || Glossary / definition pages | 1.47x || Interactive tools / calculators (see **free-tools**) | 1.38x || How-to / tutorials | 1.36x || Original research / reports | 0.80x || Ultimate guides | 0.77x || Thought leadership | 0.74x || Templates / frameworks | 0.68x |

Inside this skill

8 instruction sections

The Skill primarily produces content strategies: it gathers business and customer context, builds content pillars and topic clusters, and ranks ideas by customer impact, product fit, search potential, and resource requirements.

View source
SKILL.md:17In the instructionsOpen original file
Gather this context (ask if not provided):### 1. Business Context- What does the company do?- Who is the ideal customer?- What's the primary goal for content? (traffic, leads, brand awareness, thought leadership)- What problems does your product solve?
SKILL.md:308In the instructionsOpen original file
Score each idea on four factors:### 1. Customer Impact (40%)- How frequently did this topic come up in research?
SKILL.md:333In the instructionsOpen original file
### Scoring Template| Idea | Customer Impact (40%) | Content-Market Fit (30%) | Search Potential (20%) | Resources (10%) | Total ||------|----------------------|-------------------------|----------------------|-----------------|-------|| Topic A | 8 | 9 | 7 | 6 | 8.0 || Topic B | 6 | 7 | 9 | 8 | 7.1 |Score 1-10 per factor, multiply by the weight, sum for the total. Rank the list; make the top-scoring pieces first.

It processes user-provided keyword exports, sales or customer call transcripts, and survey data, extracting themes, pain points, objections, competitor mentions, and verbatim supporting quotes.

View source
SKILL.md:231In the instructionsOpen original file
If user provides keyword exports (Ahrefs, SEMrush, GSC), analyze for:- Topic clusters (group related keywords)- Buyer stage (awareness/consideration/decision/implementation)- Search intent (informational, commercial, transactional)- Quick wins (low competition + decent volume + high relevance)- Content gaps (keywords competitors rank for that you don't)
SKILL.md:243In the instructionsOpen original file
If user provides sales or customer call transcripts, extract:- Questions asked → FAQ content or blog posts- Pain points → problems in their own words- Objections → content to address proactively- Language patterns → exact phrases to use (voice of customer)- Competitor mentions → what they compared you toOutput content ideas with supporting quotes.
SKILL.md:254In the instructionsOpen original file
If user provides survey data, mine for:- Open-ended responses (topics and language)- Common themes (30%+ mention = high priority)- Resource requests (what they wish existed)- Content preferences (formats they want)

The distribution material is planning guidance: it proposes atomizing one flagship item across social and email channels and routing attention back to owned channels. The supplied files contain no scripts, installation steps, or automatic publishing instructions.

View source
references/content-distribution.md:60In the instructionsOpen original file
1. **Create** one exceptional flagship piece (guide, video, podcast, original research), with distribution hooks built in.2. **Atomize** it into channel-native cuts—clips, threads, carousels, quote graphics, email, subhead-posts.3. **Distribute** across owned → rented → borrowed, routing everything back to owned.4. **Engage** with the responses; capture the questions, objections, and reactions.5. **Feed back** — the engagement surfaces the next flagship topic (what resonated, what got asked), and top-performing atoms signal what to make more of.

The CMS reference recommends a draft-review-approval-publish workflow and separates author, editor, and administrator permissions; it does not instruct the user to provide access tokens to the Skill.

View source
references/headless-cms.md:80In the instructionsOpen original file
### Draft → Review → Publish Cycle1. **Draft** — Author creates or edits content2. **Review** — Editor reviews for accuracy, brand voice, SEO3. **Approve** — Stakeholder signs off4. **Schedule** — Set publish date/time5. **Publish** — Content goes live via API
references/headless-cms.md:98In the instructionsOpen original file
### Roles and Permissions| Role | Can Create | Can Edit | Can Publish | Can Delete ||------|:----------:|:--------:|:-----------:|:----------:|| Author | Yes | Own | No | Own drafts || Editor | Yes | All | Yes | Drafts || Admin | Yes | All | Yes | All |Exact permission models vary by platform. Sanity uses role-based access. Contentful has space-level roles. Strapi has granular RBAC.
Start here · InstructionsSKILL.md
content-strategy
Lines connect the instruction file to its sections, not an observed execution order. Select a section to read the source. 7 more sections are available in the original file.

File reference map

References: 2
Files making referencesReferenced content
Lines show actual file references, not execution order. Select a node to highlight its connections and inspect the files and source locations. Dashed lines include files that still need locating.
Files and check records4 files

Coverage and gaps

Content covered in each file

These are the source ranges included in this check, not a guarantee that every issue has been resolved.

  • SKILL.mdFull text included
  • references/content-distribution.mdFull text included
  • references/headless-cms.mdFull text included
  • evals/evals.jsonFull text included

This report is for the version above. We read the available code and instructions without running the skill or checking extra packages it installs. This is not a promise of safety: a different version or setup may behave differently.

  • SKILL.mdInstructions
  • evals/evals.jsonSupporting file
  • references/content-distribution.mdSupporting file
  • references/headless-cms.mdSupporting file
Lines read
836
File checksum (to compare versions)
af6548e5e98c54fa10e0eec8bfaaef9a5a950b5e49d9596d8326daa2a98f1ad2