Skip to content
Report library
Purpose / Other

Popups Skill Security Audit

What the author says it does (original text)

When the user wants to create or optimize popups, modals, overlays, slide-ins, or banners for conversion purposes. Also use when the user mentions "exit intent," "popup conversions," "modal optimization," "lead capture popup," "email popup," "announcement banner," "overlay," "collect emails with a popup," "exit popup," "scroll trigger," "sticky bar," or "notification bar." Use this for any overlay

Independent security check

Security risks found

Files checked
2
Risks found
2
Could it run dangerous commands?Looks for programs run straight after downloading, remote control of your computer, and hidden commands.No risks found
Could it expose your files or keys?Looks for uploads of files containing passwords or keys, and keys written directly in the code.Risks found: 1
Medium risk

Behavioral tracking and progressive profiling are recommended without an explicit pre-tracking consent requirement

Source references: 5
What we found

The guide recommends recording popup views, form focus, submission attempts, page visits, referral source, and engagement, then personalizing from visitor data and progressively collecting more information. It includes general GDPR advice elsewhere, but does not tie consent, minimization, or retention limits directly to this tracking.

Why this matters

If implemented as written, visitors could be persistently identified, segmented, or profiled without understanding it. Form attempts and browsing history may also enter analytics or marketing systems.

The skill recommends tracking granular events such as popup views, form focus, and submission attempts, then personalizing from visited pages and other visitor data using progressive profiling. If a site uses this to link an identifiable visitor across pages, it can create privacy, compliance, and data-misuse risks. Although the skill separately calls for clear consent and a privacy-policy link, it does not specify when this tracking requires consent, how much data to collect, or how long to retain it. Users can ask the author to bind tracking advice to consent, minimization, and retention rules.

SKILL.md:285In the instructionsOpen original file
### What to Track- Popup views- Form focus- Submission attempts- Successful submissions- Close button clicks- Outside clicks- Escape key
Show 4 other places
SKILL.md:377In the instructionsOpen original file
**Behavior Triggers**- Show based on user intent prediction- Trigger based on specific page visits- Return visitor vs. new visitor targeting- Show based on referral source
SKILL.md:412In the instructionsOpen original file
### Personalization Experiments**Dynamic Content**- Personalize popup based on visitor data- Show industry-specific content- Tailor content based on pages visited- Use progressive profiling (ask more over time)**Audience Targeting**- New vs. returning visitor messaging- Segment by traffic source- Target based on engagement level- Exclude already-converted visitors
SKILL.md:255In the instructionsOpen original file
### GDPR/Privacy- Clear consent language- Link to privacy policy- Don't pre-check opt-ins- Honor unsubscribe/preferences
SKILL.md:414In the instructionsOpen original file
**Dynamic Content**- Personalize popup based on visitor data- Show industry-specific content- Tailor content based on pages visited- Use progressive profiling (ask more over time)
Could it delete files or keep running?Looks for broad file deletion, disk overwrites, and programs set to start automatically.No risks found
Could it bypass safety checks?Looks for skipped website security checks, excessive file access, or actions that skip your approval.Risks found: 1
Medium risk

Using the mobile Back button as a popup trigger could obstruct a visitor’s attempt to leave

Source references: 2
What we found

The guide names the Back button as a mobile exit-intent alternative but does not state that normal back navigation must remain intact. An implementation that cancels navigation and forces a popup would conflict with the guide’s own instruction not to trap users.

Why this matters

Visitors may be unable to return to the previous page as expected and may have to dismiss another prompt or repeat the action. This reduces control over browser navigation and can impair accessibility.

What this evidence establishes

The source only lists the back button as a possible mobile exit-intent trigger; it does not instruct an implementation to cancel, delay, or rewrite the original navigation, and no implementation code is provided. It therefore does not establish that leaving would be obstructed. The skill instead says not to trap or trick users and to make dismissal easy. Navigation behavior after the trigger remains undefined, so users can ask the author to confirm that Back always continues to work and that browser history is not manipulated.

This assessment concerns the code and conditions shown, not proof that harm has occurred.
SKILL.md:74In the instructionsOpen original file
### Exit Intent- Detects cursor moving to close/leave- Last chance to capture value- Best for: E-commerce, lead gen- Mobile alternative: Back button or scroll up
Show 1 other places
SKILL.md:53In the instructionsOpen original file
### 3. Respect the User- Easy to dismiss- Don't trap or trick- Remember preferences- Don't ruin the experience
Could it mislead the AI or hide text?Checks the skill instructions for requests to ignore you, influence the report, or hide text in invisible characters.No risks found
Could it change links or payment recipients without asking?Looks for forced referral or payment changes combined with instructions to hide the change.No risks found

Inside this skill

8 instruction sections

This Skill is a popup conversion-optimization guide with no executable scripts, installation steps, or network-transmission instructions. It first directs the agent to read local product-marketing context, then recommends triggers, targeting, copy, frequency, privacy, and accessibility practices.

View source
SKILL.md:14In the instructionsOpen original file
**Check for product marketing context first:**If `.agents/product-marketing.md` exists (or `.claude/product-marketing.md`, or the legacy `product-marketing-context.md` filename, in older setups), read it before asking questions. Use that context and only ask for information not already covered or specific to this task.
SKILL.md:301In the instructionsOpen original file
## Output Format### Popup Design- **Type**: Email capture, lead magnet, etc.- **Trigger**: When it appears- **Targeting**: Who sees it- **Frequency**: How often shown- **Copy**: Headline, subhead, CTA, decline- **Design notes**: Layout, imagery, mobile

The guide explicitly advocates easy dismissal, remembering dismissals, excluding converted users, and applying consent, unsubscribe, and accessibility requirements. These constraints reduce manipulation and repeated interruption risks, but enforcement depends on the later implementation.

View source
SKILL.md:53In the instructionsOpen original file
### 3. Respect the User- Easy to dismiss- Don't trap or trick- Remember preferences- Don't ruin the experience
SKILL.md:233In the instructionsOpen original file
### Frequency Capping- Show maximum once per session- Remember dismissals (cookie/localStorage)- 7-30 days before showing again- Respect user choice
SKILL.md:253In the instructionsOpen original file
## Compliance and Accessibility### GDPR/Privacy- Clear consent language- Link to privacy policy- Don't pre-check opt-ins- Honor unsubscribe/preferences### Accessibility- Keyboard navigable (Tab, Enter, Esc)- Focus trap while open- Screen reader compatible- Sufficient color contrast- Don't rely on color alone
Start here · InstructionsSKILL.md
popups
Lines connect the instruction file to its sections, not an observed execution order. Select a section to read the source. 6 more sections are available in the original file.
Files and check records2 files

Coverage and gaps

Content covered in each file

These are the source ranges included in this check, not a guarantee that every issue has been resolved.

  • SKILL.mdFull text included
  • evals/evals.jsonFull text included

This report is for the version above. We read the available code and instructions without running the skill or checking extra packages it installs. This is not a promise of safety: a different version or setup may behave differently.

  • SKILL.mdInstructions
  • evals/evals.jsonSupporting file
Lines read
550
File checksum (to compare versions)
5a320d004010de7d3f2a2bc96d045ea91c47af3d3abb73b5d7f83bc976825f23