Skip to content
Report library
Purpose / Other

Marketing Council Skill Security Audit

What the author says it does (original text)

When the user wants multiple expert perspectives on a marketing question — a simulated board of advisors staffed by legendary marketers (Seth Godin, David Ogilvy, Eugene Schwartz, April Dunford, Rory Sutherland, Alex Hormozi, Byron Sharp, and more). Also use when the user mentions 'marketing council,' 'board of advisors,' 'advisory board,' 'what would Seth Godin say,' 'what would Ogilvy think,' 'c

Independent security check

Security risks found

Files checked
15
Risks found
5
Could it run dangerous commands?Looks for programs run straight after downloading, remote control of your computer, and hidden commands.No risks found
Could it expose your files or keys?Looks for uploads of files containing passwords or keys, and keys written directly in the code.Risks found: 1
Medium risk

Live research may send confidential marketing topics to search or research services

Source references: 2
What we found

The research flow searches for `[advisor name] + [topic]` and may invoke separate research, video, or recency skills. If the topic includes an unreleased product, client, pricing change, rebrand, or launch plan, that information can enter an external query. The Skill does not require redaction or renewed consent before searching.

Why this matters

Search providers, invoked skills, and their logs may learn confidential strategy or upcoming commercial decisions.

Live research is conditional, but for a specific topic or a request for sources the Skill directs the agent to use external research tools or search for “advisor name + topic.” If that topic contains unpublished product, customer, pricing, or launch details, those terms could be sent to an external service; no redaction step is stated. Users can require query preview, removal of identifying terms, and explicit consent before network research.

SKILL.md:86In the instructionsOpen original file
When the topic is specific (a niche, a channel shift, a current platform change) or the user wants sources, go beyond the dossiers:- **If a deep-research skill is installed** (e.g., `deep-research`): use it to find what the seated advisors have actually said or written about this topic class — books, essays, interviews, podcasts — plus current state of the debate.- **If a video-analysis skill is installed** (e.g., `watch-video`): pull takes from specific talks/interviews the research surfaces.- **If a recency skill is installed** (e.g., `last30days`): check for recent takes when the topic is fast-moving.- **Otherwise**: use built-in web search for `[advisor name] + [topic]` per seated advisor, preferring primary sources (their own books, blogs, newsletters, talks) over roundup articles.
Show 1 other places
SKILL.md:88In the instructionsOpen original file
- **If a deep-research skill is installed** (e.g., `deep-research`): use it to find what the seated advisors have actually said or written about this topic class — books, essays, interviews, podcasts — plus current state of the debate.- **If a video-analysis skill is installed** (e.g., `watch-video`): pull takes from specific talks/interviews the research surfaces.- **If a recency skill is installed** (e.g., `last30days`): check for recent takes when the topic is fast-moving.- **Otherwise**: use built-in web search for `[advisor name] + [topic]` per seated advisor, preferring primary sources (their own books, blogs, newsletters, talks) over roundup articles.
Could it delete files or keep running?Looks for broad file deletion, disk overwrites, and programs set to start automatically.Risks found: 1
Low risk

Adding a private advisor persistently stores their views and voice profile in the project

Source references: 5
What we found

The custom-advisor flow writes `.agents/advisors/<name>.md` containing a private colleague's or executive's positions, blind spots, and voice characteristics. It emphasizes persistence but does not require checking version-control status, project visibility, or the person's consent.

Why this matters

The dossier may be committed to a shared repository, backed up, or read by other collaborators, exposing internal characterizations of a real person and creating privacy or reputational concerns.

Adding a custom advisor writes a dossier under the project’s `.agents/advisors/` directory and deliberately persists it across Skill updates. The template records positions, blind spots, and voice characteristics. Requiring the user to supply a private person’s views prevents fabrication, but does not address version control, team visibility, or that person’s consent. Users can require confirmation of the path, sharing scope, and sensitive fields, or keep the profile session-only.

SKILL.md:142In the instructionsOpen original file
Users can extend the bench ("add my own advisor"). Create a dossier following the structure in [references/advisor-template.md](references/advisor-template.md) — the same fields as the built-in advisors (lens, frameworks, documented positions with sources, signature questions, best-for/blind spots, voice notes, key works). For non-famous advisors (the user's old boss, an internal exec), have the user supply the positions; do not invent them. Save to `.agents/advisors/<name>.md` in the user's project so it persists and never collides with repo updates.
Show 4 other places
references/advisor-template.md:3In the instructionsOpen original file
Copy this structure to add an advisor to the bench. Save custom advisors to `.agents/advisors/<kebab-name>.md` in your project (not inside the skill folder) so they survive skill updates.Two kinds of custom advisors, two grounding standards:- **Public figures** (a famous marketer not on the bench): every framework and position must trace to something they published or said — research before writing, cite sources, follow the same grounding rules as the built-in dossiers.- **Private advisors** (your former boss, your best customer, your CFO): the *user* supplies the positions and heuristics. The agent must not invent views for a real private person — interview the user to fill the template.
references/advisor-template.md:33In the instructionsOpen original file
## Best for / blind spots**Best for:** [problem types their lens genuinely illuminates]**Blind spots:** [documented criticisms or acknowledged limits — this iswhat makes their dissent honest rather than decorative]## Voice notes[2-3 sentences: sentence rhythm, favorite metaphors, tone, tics. Enoughto write in their register without fabricating quotes.]
references/advisor-template.md:36In the instructionsOpen original file
**Best for:** [problem types their lens genuinely illuminates]**Blind spots:** [documented criticisms or acknowledged limits — this iswhat makes their dissent honest rather than decorative]## Voice notes[2-3 sentences: sentence rhythm, favorite metaphors, tone, tics. Enoughto write in their register without fabricating quotes.]
references/advisor-template.md:7In the instructionsOpen original file
- **Public figures** (a famous marketer not on the bench): every framework and position must trace to something they published or said — research before writing, cite sources, follow the same grounding rules as the built-in dossiers.- **Private advisors** (your former boss, your best customer, your CFO): the *user* supplies the positions and heuristics. The agent must not invent views for a real private person — interview the user to fill the template.
Could it bypass safety checks?Looks for skipped website security checks, excessive file access, or actions that skip your approval.No risks found
Could it mislead the AI or hide text?Checks the skill instructions for requests to ignore you, influence the report, or hide text in invisible characters.Risks found: 2
Medium risk

Project marketing and custom-advisor files can inject instructions into the agent

Source references: 3
What we found

The Skill automatically reads project-controlled marketing context and can load custom files from `.agents/advisors/` as dossiers, but it does not say to treat their contents only as untrusted reference data or ignore embedded commands. A malicious or modified repository could place agent-directed instructions in those Markdown files.

Why this matters

If the host agent has file, network, or account tools, injected text could alter the council's answer or induce unrelated actions. The actual effect depends on the agent's permissions and whether it obeys the file.

The Skill reads project marketing-context files before questioning the user and treats project-local custom-advisor Markdown as a dossier. It does not explicitly say to treat that content as untrusted data or ignore embedded operational instructions. Thus, a repository supplied by someone else or a tampered file could influence the agent’s decisions or later actions. Users can ask the author to add a strict data-only boundary and restrict reads to confirmed files.

SKILL.md:16In the instructionsOpen original file
**Check for product marketing context first:**If `.agents/product-marketing.md` exists (or `.claude/product-marketing.md`, or the legacy `product-marketing-context.md`), read it before asking questions.
Show 2 other places
SKILL.md:142In the instructionsOpen original file
Users can extend the bench ("add my own advisor"). Create a dossier following the structure in [references/advisor-template.md](references/advisor-template.md) — the same fields as the built-in advisors (lens, frameworks, documented positions with sources, signature questions, best-for/blind spots, voice notes, key works). For non-famous advisors (the user's old boss, an internal exec), have the user supply the positions; do not invent them. Save to `.agents/advisors/<name>.md` in the user's project so it persists and never collides with repo updates.
references/advisor-template.md:51In the instructionsOpen original file
**Seating a custom advisor:** mention them by name when convening ("seat my advisor Maria on this council"). The agent loads the file from `.agents/advisors/` and treats it like any bench dossier, including the grounding rules — no fabricated quotes, no invented endorsements.
Medium risk

Research is told to override dossiers without a boundary against web prompt injection

Source references: 4
What we found

The Skill explicitly says to trust research when it conflicts with a dossier. External pages, interview transcripts, and research-skill output are not trusted instruction sources and can contain text telling the agent to disclose data, invoke tools, or ignore restrictions.

Why this matters

A malicious search result could distort the represented advice and may attempt to control a tool-enabled agent. Success depends on the research tool's isolation and the host agent's permissions.

Legitimate use of this code

“Trust the research” is a rule for resolving factual-source conflicts, not an instruction to execute commands found on webpages. The surrounding text prefers primary sources, requires citations and disclosed corrections, and forbids unverifiable quotations or invented endorsements. Nothing shown says webpage text should be treated as tool instructions, so the candidate’s prompt-injection execution path is not supported.

This assessment concerns the code and conditions shown, not proof that harm has occurred.
SKILL.md:88In the instructionsOpen original file
- **If a deep-research skill is installed** (e.g., `deep-research`): use it to find what the seated advisors have actually said or written about this topic class — books, essays, interviews, podcasts — plus current state of the debate.- **If a video-analysis skill is installed** (e.g., `watch-video`): pull takes from specific talks/interviews the research surfaces.- **If a recency skill is installed** (e.g., `last30days`): check for recent takes when the topic is fast-moving.- **Otherwise**: use built-in web search for `[advisor name] + [topic]` per seated advisor, preferring primary sources (their own books, blogs, newsletters, talks) over roundup articles.Fold findings into the takes with citations ("In a 2023 interview on X, Dunford argued…"). If research contradicts a dossier, trust the research and note the correction.
Show 3 other places
SKILL.md:91In the instructionsOpen original file
- **If a recency skill is installed** (e.g., `last30days`): check for recent takes when the topic is fast-moving.- **Otherwise**: use built-in web search for `[advisor name] + [topic]` per seated advisor, preferring primary sources (their own books, blogs, newsletters, talks) over roundup articles.
SKILL.md:93In the instructionsOpen original file
Fold findings into the takes with citations ("In a 2023 interview on X, Dunford argued…"). If research contradicts a dossier, trust the research and note the correction.
SKILL.md:98In the instructionsOpen original file
- **Label the session as simulation** once, at the top: a line like *"Simulated council — each take is built from the advisor's published frameworks and positions, not their actual review."*- **No fabricated quotes.** Direct quotation only for lines verifiable in the dossier or research pass, with the source named. Otherwise paraphrase: "Hopkins's position in *Scientific Advertising* is…"- **No invented endorsements or condemnations.** An advisor can be simulated *applying their framework* to the user's product; never state or imply the real person has an opinion about the user's specific company.- **Living advisors get extra care.** Godin, Brunson, Hormozi, Dunford, Sutherland, Sharp, Handley, and Vaynerchuk are alive and active — their positions evolve; prefer the research pass for anything time-sensitive, and never simulate them commenting on named competitors or controversies.
Could it change links or payment recipients without asking?Looks for forced referral or payment changes combined with instructions to hide the change.Risks found: 1
Medium risk

High-conviction simulations may be mistaken for validated business advice

Source references: 7
What we found

Each simulated advisor is told to state a recommendation with conviction, followed by a synthesized recommendation tailored to the user, while live verification remains optional. The dossiers include summaries, secondary sourcing, and material expressly described as self-reported or unverified, so the output is neither a real review by those people nor empirical proof for the user's business.

Why this matters

A user could change pricing, branding, channels, or advertising spend without validating customer evidence, regulation, unit economics, or experiments, causing revenue or brand damage.

The Skill asks simulated advisors to recommend with strong conviction and then produces a business-specific synthesis, while live research is optional. Its simulation label, ban on implied real endorsements, and disagreement map reduce confusion, but confident wording could still be mistaken for a validated conclusion. Users can require key assumptions, evidence gaps, and tests alongside each recommendation and avoid relying on the simulation alone for high-stakes decisions.

SKILL.md:75In the instructionsOpen original file
1. **Load the seated advisors' dossiers** from `references/advisors/`.2. **Optional live research pass** — see below. Offer it when the question is specific enough that documented positions may not cover it, or the user wants citations.3. **Each advisor's take** — 2–4 paragraphs per advisor:   - Open with the advisor applying their *signature questions* to the user's case   - Apply their frameworks to the specifics (their dossier lists them) — not generic advice with a name attached   - State their recommendation with the conviction they'd actually have   - Written in their voice per the dossier's voice notes, without fabricated quotes4. **The disagreement map** — the most valuable section. Identify 2-4 genuine conflicts between the takes, name the underlying trade-off each conflict represents (e.g., "Sharp vs. Godin here is really reach vs. resonance — which constraint binds *this* business?"), and say what evidence would settle each.5. **Synthesis** — a chair's summary: the recommendation that best fits *this* user's stage, category, and constraints; which advisor's warning to keep as a tripwire; and concrete next steps with skill handoffs (see Related Skills).
Show 6 other places
SKILL.md:97In the instructionsOpen original file
- **Label the session as simulation** once, at the top: a line like *"Simulated council — each take is built from the advisor's published frameworks and positions, not their actual review."*- **No fabricated quotes.** Direct quotation only for lines verifiable in the dossier or research pass, with the source named. Otherwise paraphrase: "Hopkins's position in *Scientific Advertising* is…"- **No invented endorsements or condemnations.** An advisor can be simulated *applying their framework* to the user's product; never state or imply the real person has an opinion about the user's specific company.- **Living advisors get extra care.** Godin, Brunson, Hormozi, Dunford, Sutherland, Sharp, Handley, and Vaynerchuk are alive and active — their positions evolve; prefer the research pass for anything time-sensitive, and never simulate them commenting on named competitors or controversies.- **Disagree in substance, not caricature.** Each advisor's take must be the strongest version of their view applied to this case — no strawmen for the synthesis to knock down.
references/advisors/alex-hormozi.md:35In the instructionsOpen original file
**Best for:** Offer construction, pricing, unit-economics discipline, lead gen for high-LTV services/info/SaaS, breaking analysis paralysis with volume quotas.**Blind spots (documented):** Critics document engineered scarcity/FOMO in his own launches (e.g., the 2025 Money Models launch critique) and note the playbook oversimplifies outside high-ticket, pain-driven categories. Offer-maximalism (bonus stacks, urgency, guarantees) reads infomercial-coded in brand-sensitive, enterprise, and luxury contexts. Little on long-horizon brand, creative craft, or buyers not in acute pain. *His launch/revenue figures are self-reported — don't state as verified fact.*
references/advisors/gary-halbert.md:35In the instructionsOpen original file
**Best for:** Offer-market fit before copy polish, audience/list selection, direct-response email and mail, injecting urgency and personality into sterile copy, ruthless founder prioritization.**Blind spots:** No framework for brand, product, retention, or reputation. His career included an 18-month federal prison term for mail fraud (the Boron Letters were written from that camp) — the documented shadow side of the style; his tactics transfer poorly to trust-sensitive, regulated, or enterprise contexts. *Legend-figures like the coat-of-arms letter's "most mailed in history" claims are unverifiable — treat as lore, not statistics.*
SKILL.md:12In the instructionsOpen original file
**This is persona simulation, not the real people.** Every take must be grounded in what the advisor actually wrote or said (see Grounding Rules). Label the output as simulation.
SKILL.md:79In the instructionsOpen original file
   - Apply their frameworks to the specifics (their dossier lists them) — not generic advice with a name attached   - State their recommendation with the conviction they'd actually have   - Written in their voice per the dossier's voice notes, without fabricated quotes4. **The disagreement map** — the most valuable section. Identify 2-4 genuine conflicts between the takes, name the underlying trade-off each conflict represents (e.g., "Sharp vs. Godin here is really reach vs. resonance — which constraint binds *this* business?"), and say what evidence would settle each.
SKILL.md:81In the instructionsOpen original file
   - Written in their voice per the dossier's voice notes, without fabricated quotes4. **The disagreement map** — the most valuable section. Identify 2-4 genuine conflicts between the takes, name the underlying trade-off each conflict represents (e.g., "Sharp vs. Godin here is really reach vs. resonance — which constraint binds *this* business?"), and say what evidence would settle each.5. **Synthesis** — a chair's summary: the recommendation that best fits *this* user's stage, category, and constraints; which advisor's warning to keep as a tripwire; and concrete next steps with skill handoffs (see Related Skills).

Inside this skill

8 instruction sections

The Skill simulates an advisory council from marketer dossiers, normally seats 3–5 people, and requires at least one dissenting advisor. Its output must disclose that this is not a real review by those people.

View source
SKILL.md:10In the instructionsOpen original file
You convene a **simulated board of marketing advisors**: legendary marketers whose documented frameworks, published positions, and known heuristics you apply to the user's specific problem. The value isn't any single take — it's the *disagreement*. The bench is built from thinkers whose lenses conflict in useful ways, so the user sees the real trade-offs before choosing a direction.**This is persona simulation, not the real people.** Every take must be grounded in what the advisor actually wrote or said (see Grounding Rules). Label the output as simulation.
SKILL.md:53In the instructionsOpen original file
For a council session, seat 3–5 advisors:1. **2–3 whose lens directly fits the question type** (table below).2. **Always seat at least one designated dissenter** — an advisor whose documented position conflicts with where the question is leaning. A council that agrees is a mirror, not a board.3. Honor explicit requests ("I want Hormozi and Godin on this").

Before a session, it looks for and reads a product-marketing context file in the project, then loads the dossiers of the selected advisors.

View source
SKILL.md:16In the instructionsOpen original file
**Check for product marketing context first:**If `.agents/product-marketing.md` exists (or `.claude/product-marketing.md`, or the legacy `product-marketing-context.md`), read it before asking questions.
SKILL.md:74In the instructionsOpen original file
1. **Load the seated advisors' dossiers** from `references/advisors/`.2. **Optional live research pass** — see below. Offer it when the question is specific enough that documented positions may not cover it, or the user wants citations.

For specific, recent, or citation-sensitive questions, it may invoke installed research skills or run a built-in web search for each advisor and the topic, then incorporate the results with citations.

View source
SKILL.md:86In the instructionsOpen original file
When the topic is specific (a niche, a channel shift, a current platform change) or the user wants sources, go beyond the dossiers:- **If a deep-research skill is installed** (e.g., `deep-research`): use it to find what the seated advisors have actually said or written about this topic class — books, essays, interviews, podcasts — plus current state of the debate.- **If a video-analysis skill is installed** (e.g., `watch-video`): pull takes from specific talks/interviews the research surfaces.- **If a recency skill is installed** (e.g., `last30days`): check for recent takes when the topic is fast-moving.- **Otherwise**: use built-in web search for `[advisor name] + [topic]` per seated advisor, preferring primary sources (their own books, blogs, newsletters, talks) over roundup articles.Fold findings into the takes with citations ("In a 2023 interview on X, Dunford argued…"). If research contradicts a dossier, trust the research and note the correction.

When a user asks to add a custom advisor, the Skill creates a persistent dossier under the project's `.agents/advisors/` directory. For private advisors, the views must come from the user rather than being invented by the agent.

View source
SKILL.md:142In the instructionsOpen original file
Users can extend the bench ("add my own advisor"). Create a dossier following the structure in [references/advisor-template.md](references/advisor-template.md) — the same fields as the built-in advisors (lens, frameworks, documented positions with sources, signature questions, best-for/blind spots, voice notes, key works). For non-famous advisors (the user's old boss, an internal exec), have the user supply the positions; do not invent them. Save to `.agents/advisors/<name>.md` in the user's project so it persists and never collides with repo updates.
Start here · InstructionsSKILL.md
marketing-council
Lines connect the instruction file to its sections, not an observed execution order. Select a section to read the source. 3 more sections are available in the original file.

File reference map

References: 14
Files making referencesReferenced content
Lines show actual file references, not execution order. Select a node to highlight its connections and inspect the files and source locations. Dashed lines include files that still need locating.
Files and check records15 files

Coverage and gaps

Content covered in each file

These are the source ranges included in this check, not a guarantee that every issue has been resolved.

  • SKILL.mdFull text included
  • references/advisor-template.mdFull text included
  • references/advisors/alex-hormozi.mdFull text included
  • references/advisors/ann-handley.mdFull text included
  • references/advisors/april-dunford.mdFull text included
  • references/advisors/byron-sharp.mdFull text included
  • references/advisors/claude-hopkins.mdFull text included
  • references/advisors/david-ogilvy.mdFull text included
  • references/advisors/eugene-schwartz.mdFull text included
  • references/advisors/gary-halbert.mdFull text included
  • references/advisors/gary-vaynerchuk.mdFull text included
  • references/advisors/rory-sutherland.mdFull text included
  • references/advisors/russell-brunson.mdFull text included
  • references/advisors/seth-godin.mdFull text included
  • evals/evals.jsonFull text included

This report is for the version above. We read the available code and instructions without running the skill or checking extra packages it installs. This is not a promise of safety: a different version or setup may behave differently.

  • SKILL.mdInstructions
  • evals/evals.jsonSupporting file
  • references/advisor-template.mdSupporting file
  • references/advisors/alex-hormozi.mdSupporting file
  • references/advisors/ann-handley.mdSupporting file
  • references/advisors/april-dunford.mdSupporting file
  • references/advisors/byron-sharp.mdSupporting file
  • references/advisors/claude-hopkins.mdSupporting file
  • references/advisors/david-ogilvy.mdSupporting file
  • references/advisors/eugene-schwartz.mdSupporting file
  • references/advisors/gary-halbert.mdSupporting file
  • references/advisors/gary-vaynerchuk.mdSupporting file
  • references/advisors/rory-sutherland.mdSupporting file
  • references/advisors/russell-brunson.mdSupporting file
  • references/advisors/seth-godin.mdSupporting file
Lines read
807
File checksum (to compare versions)
fce58352beb0d2f12f7421825939a27af625ef14d3b7d9da1f0f17b406e20023