Skip to content
Report library
Purpose / Data analysis

Sales Enablement Skill Security Audit

What the author says it does (original text)

When the user wants to create sales collateral, pitch decks, one-pagers, objection handling docs, or demo scripts. Also use when the user mentions 'sales deck,' 'pitch deck,' 'one-pager,' 'leave-behind,' 'objection handling,' 'deal-specific ROI analysis,' 'demo script,' 'talk track,' 'sales playbook,' 'proposal template,' 'buyer persona card,' 'help my sales team,' 'sales materials,' or 'what shou

Independent security check

Security risks found

Files checked
6
Risks found
1
Could it run dangerous commands?Looks for programs run straight after downloading, remote control of your computer, and hidden commands.No risks found
Could it expose your files or keys?Looks for uploads of files containing passwords or keys, and keys written directly in the code.Risks found: 1
Medium risk

Local product-marketing information may flow into externally shared sales material

Source references: 4
What we found

The Skill proactively reads a product-marketing document from hidden configuration directories or a legacy filename and directs the agent to use that context. It also tells proposals to reference prospect pain points and named stakeholders. The source does not require separating public from confidential local information or obtaining item-by-item approval before use.

Why this matters

If the local context contains non-public pricing, roadmap details, customer names, internal metrics, or contact information, those details could enter a deck, proposal, or one-pager and be disclosed when the user later shares it with a prospect.

The active instructions require automatically reading local product-marketing context and using it, while proposal customization calls for specific customer pain points and named stakeholders. If those files contain internal positioning, customer identities, or deal details and the output is shared with prospects, non-public information could be exposed unintentionally. The evidence does not show that disclosure necessarily occurs, but it provides no public-information check or item-by-item approval. Users can require public-only sourcing, redaction, and pre-release confirmation.

SKILL.md:14In the instructionsOpen original file
**Check for product marketing context first:**If `.agents/product-marketing.md` exists (or `.claude/product-marketing.md`, or the legacy `product-marketing-context.md` filename, in older setups), read it before asking questions. Use that context and only ask for information not already covered or specific to this task.
Show 3 other places
SKILL.md:252In the instructionsOpen original file
- Mirror their language from discovery calls- Reference specific pain points they mentioned- Include only relevant case studies (same industry or use case)- Name the stakeholders you've spoken with
SKILL.md:250In the instructionsOpen original file
### Customization Guidance- Mirror their language from discovery calls- Reference specific pain points they mentioned- Include only relevant case studies (same industry or use case)- Name the stakeholders you've spoken with
SKILL.md:313In the instructionsOpen original file
## Output FormatDeliver the right format for each asset type:| Asset | Deliverable ||-------|-------------|| Sales deck | Slide-by-slide outline with headline, body copy, and speaker notes || One-pager | Full copy with layout guidance (visual hierarchy, sections) || Objection doc | Table format: objection, response, proof point, follow-up || Demo script | Scene-by-scene with timing, talk track, and interaction points || ROI calculator | Input fields, formulas, output display with sample data || Playbook | Structured document with table of contents and sections || Persona card | One-page card format per persona || Proposal | Section-by-section copy with customization notes |
Could it delete files or keep running?Looks for broad file deletion, disk overwrites, and programs set to start automatically.No risks found
Could it bypass safety checks?Looks for skipped website security checks, excessive file access, or actions that skip your approval.No risks found
Could it mislead the AI or hide text?Checks the skill instructions for requests to ignore you, influence the report, or hide text in invisible characters.No risks found
Could it change links or payment recipients without asking?Looks for forced referral or payment changes combined with instructions to hide the change.No risks found

Inside this skill

8 instruction sections

This Skill generates sales decks, one-pagers, objection documents, demo scripts, ROI calculators, playbooks, and proposals. The supplied source consists of Markdown instructions and templates, with no shown step that automatically sends materials, accesses accounts, or executes scripts.

View source
SKILL.md:315In the instructionsOpen original file
Deliver the right format for each asset type:| Asset | Deliverable ||-------|-------------|| Sales deck | Slide-by-slide outline with headline, body copy, and speaker notes || One-pager | Full copy with layout guidance (visual hierarchy, sections) || Objection doc | Table format: objection, response, proof point, follow-up || Demo script | Scene-by-scene with timing, talk track, and interaction points || ROI calculator | Input fields, formulas, output display with sample data || Playbook | Structured document with table of contents and sections || Persona card | One-page card format per persona || Proposal | Section-by-section copy with customization notes |

It requires reading project-local product-marketing context first and then asking only for missing information. Generated material may therefore incorporate local information that the user did not restate in the current request.

View source
SKILL.md:14In the instructionsOpen original file
**Check for product marketing context first:**If `.agents/product-marketing.md` exists (or `.claude/product-marketing.md`, or the legacy `product-marketing-context.md` filename, in older setups), read it before asking questions. Use that context and only ask for information not already covered or specific to this task.

The ROI guidance calls for returns based on prospect inputs or industry benchmarks and explicitly warns against unrealistic projections, hidden math, or generic figures unrelated to the prospect.

View source
references/deck-frameworks.md:151In the instructionsOpen original file
**What to include:**- Expected return based on their inputs or industry benchmarks- Payback period- Total value over 1-3 years- Comparison to cost of inaction**What to avoid:**- Unrealistic projections- ROI without showing your math- Generic numbers not tied to their situation
Start here · InstructionsSKILL.md
sales-enablement
Lines connect the instruction file to its sections, not an observed execution order. Select a section to read the source. 7 more sections are available in the original file.

File reference map

References: 4
Files making referencesReferenced content
Lines show actual file references, not execution order. Select a node to highlight its connections and inspect the files and source locations. Dashed lines include files that still need locating.
Files and check records6 files

Coverage and gaps

Content covered in each file

These are the source ranges included in this check, not a guarantee that every issue has been resolved.

  • SKILL.mdFull text included
  • references/deck-frameworks.mdFull text included
  • references/demo-scripts.mdFull text included
  • references/objection-library.mdFull text included
  • references/one-pager-templates.mdFull text included
  • evals/evals.jsonFull text included

This report is for the version above. We read the available code and instructions without running the skill or checking extra packages it installs. This is not a promise of safety: a different version or setup may behave differently.

  • SKILL.mdInstructions
  • evals/evals.jsonSupporting file
  • references/deck-frameworks.mdSupporting file
  • references/demo-scripts.mdSupporting file
  • references/objection-library.mdSupporting file
  • references/one-pager-templates.mdSupporting file
Lines read
1,552
File checksum (to compare versions)
6ee45019d03b40c75ab8e13fd01d41e8dda5d0048173b3bad32ebe5aa9b0356b