Skip to content
Report library
Purpose / Other

Sms Skill Security Audit

What the author says it does (original text)

When the user wants to plan, build, or optimize SMS or MMS marketing — including welcome flows, abandoned cart texts, post-purchase, win-back, promotional sends, or transactional/auth SMS. Also use when the user mentions "SMS marketing," "text message campaigns," "SMS sequence," "SMS automation," "abandoned cart text," "post-purchase SMS," "Klaviyo SMS," "Postscript," "Attentive," "Twilio," "A2P 1

Independent security check

Security risks found

Files checked
5
Risks found
2
Could it run dangerous commands?Looks for programs run straight after downloading, remote control of your computer, and hidden commands.No risks found
Could it expose your files or keys?Looks for uploads of files containing passwords or keys, and keys written directly in the code.No risks found
Could it delete files or keep running?Looks for broad file deletion, disk overwrites, and programs set to start automatically.No risks found
Could it bypass safety checks?Looks for skipped website security checks, excessive file access, or actions that skip your approval.Risks found: 1
Medium risk

Account-security alert template directs recipients through an opaque short link

Source references: 2
What we found

The Skill calls short links mandatory and uses one in a new-device sign-in alert. A shortened URL hides the destination domain, preventing recipients from readily confirming that it belongs to their account provider.

Why this matters

This design conditions recipients to click unverifiable links in security alerts. Attackers can imitate the format in phishing messages, potentially stealing passwords, verification codes, or account sessions.

The source supports this risk. The Skill makes short links mandatory and uses `[short.link]` in a new-device sign-in alert that prompts action on a potentially compromised account. If the deployed short domain is unclear or not brand-controlled, recipients cannot verify the destination before clicking, weakening phishing detection and account-security decisions; no exception or trusted-domain constraint is stated for security alerts. Users can require a recognizable first-party domain, an option to open the official app directly, and an allowlist for redirect domains.

SKILL.md:126In the instructionsOpen original file
### 5. One CTA, one linkShort links are mandatory (`klvy.co`, `txt.attn.tv`, branded short domain). Track UTM params on every link.
Show 1 other places
references/sequence-templates.md:206In the instructionsOpen original file
### Account alert```[Brand]: Sign-in from new device in [location]. Wasn't you? Secure: [short.link]```
Could it mislead the AI or hide text?Checks the skill instructions for requests to ignore you, influence the report, or hide text in invisible characters.No risks found
Could it change links or payment recipients without asking?Looks for forced referral or payment changes combined with instructions to hide the change.Risks found: 1
Medium risk

Generic promotional templates omit requirements the Skill lists for Canadian messages

Source references: 3
What we found

The Skill covers Canada and says every message must contain sender identification, a mailing address, contact details, and an unsubscribe mechanism. Its ready-to-use promotional templates contain only a brand name, offer, and short link, without an address, contact method, or opt-out instruction.

Why this matters

Deploying these templates unchanged to Canadian recipients may violate the Skill's own stated CASL requirements, exposing the user to complaints, delivery restrictions, reputational damage, or regulatory penalties.

The source supports this risk. Its Canada section says every message must include legal identity, a mailing address, contact details, and an unsubscribe mechanism, while the reusable promotional template contains only a brand name, offer, and short link and is not marked as unsuitable for Canada. Using it unchanged for Canadian marketing could omit the Skill’s own listed CASL elements, increasing complaint, account, and penalty exposure. Users can require Canada-specific templates or jurisdiction-by-jurisdiction validation and obtain Canadian compliance review before sending.

references/compliance.md:155In the instructionsOpen original file
### Every message must include- Sender identification (legal name + any operating names)- Mailing address- Phone, email, or website contact- Unsubscribe mechanism that works within 10 business days
Show 2 other places
references/sequence-templates.md:150In the instructionsOpen original file
### Flash sale (single send)```From [Brand]: 24-HOUR FLASH: 25% off everything with FLASH25. Ends midnight: [short.link]```~94 chars / 1 segment.
references/sequence-templates.md:148In the instructionsOpen original file
## Promotional / Campaign Sends### Flash sale (single send)```From [Brand]: 24-HOUR FLASH: 25% off everything with FLASH25. Ends midnight: [short.link]```~94 chars / 1 segment.

Inside this skill

8 instruction sections

This Skill is advisory guidance and copy templates; it contains no executable scripts. It first reads a product-marketing context file when present, then gathers jurisdiction, list size, platform, and compliance details before producing strategy, message sequences, platform recommendations, and measurement plans.

View source
SKILL.md:14In the instructionsOpen original file
**Check for product marketing context first:**If `.agents/product-marketing.md` exists (or `.claude/product-marketing.md`, or the legacy `product-marketing-context.md` filename, in older setups), read it before asking questions. Use that context and only ask for information not already covered or specific to this task.
SKILL.md:272In the instructionsOpen original file
When the user asks for an SMS plan, return:1. **Compliance check**: Are they registered for A2P 10DLC (if US)? Is the opt-in mechanism compliant? Flag blockers first.2. **Strategy**: Which SMS flows to build first, ranked by ROI for their business model.3. **Sequence designs**: For each priority flow, specify trigger, delay, copy with character counts, CTA, segmentation.4. **Platform recommendation**: Based on stack, list size, and complexity.5. **Measurement plan**: KPIs, benchmarks, A/B test queue.6. **Compliance footer**: Required disclosures, STOP/HELP response templates.

It explicitly distinguishes marketing from transactional messaging and requires written consent for marketing, prompt opt-out handling, recipient-local quiet hours, and auditable consent records.

View source
SKILL.md:67In the instructionsOpen original file
1. **Express written consent** required for marketing SMS. Implied consent doesn't count.2. **Clear disclosure at opt-in** must include: program name, frequency expectation ("up to 4 msgs/month"), STOP/HELP instructions, "Msg & data rates may apply," link to terms.3. **Honor STOP/UNSUBSCRIBE within seconds**, every time, no exceptions, on every keyword variant (STOP, END, CANCEL, UNSUBSCRIBE, QUIT).4. **Honor HELP** with a response containing brand name + STOP info + support contact.5. **Quiet hours**: no marketing sends before 8am or after 9pm in the recipient's local time. Carrier rules and state laws (e.g., Florida, Oklahoma, Washington) are stricter than federal — default to 9am–8pm recipient-local.6. **Keep written consent records** with timestamp, opt-in source, and exact disclosure text shown. Auditable.
references/compliance.md:17In the instructionsOpen original file
| Type | What it covers | How to capture ||------|---------------|----------------|| **Express written consent** | Marketing SMS (sales, promotions, offers) | Checkbox + clear disclosure language, captured electronically with timestamp || **Express consent (non-written)** | Informational/transactional (delivery, account alerts) | Phone number provided during transaction with awareness it'll be used to text || **Established business relationship** | NOT sufficient for marketing SMS | Doesn't apply |

Sending is not automated within this package; implementation is delegated to an external tools registry and vendor integration guides. The provided source does not allow review of whether those external tools read contacts, use credentials, or send messages directly.

View source
SKILL.md:312In the instructionsOpen original file
## Tool IntegrationsFor implementation, see the [tools registry](../../tools/REGISTRY.md). Key SMS tools:| Tool | Best For | MCP | Guide ||------|----------|:---:|-------|| **Klaviyo** | E-commerce email + SMS combined | ✓ | [klaviyo.md](../../tools/integrations/klaviyo.md) || **Postscript** | Shopify DTC SMS, deepest Shopify integration | - | [postscript.md](../../tools/integrations/postscript.md) || **Attentive** | Mid-market+ DTC SMS, full-service | - | [attentive.md](../../tools/integrations/attentive.md) || **Twilio** | Raw API for custom builds, transactional, dev-first | - | [twilio.md](../../tools/integrations/twilio.md) || **Plivo** | Twilio alternative, lower per-send cost | - | [plivo.md](../../tools/integrations/plivo.md) |
Start here · InstructionsSKILL.md
sms
Lines connect the instruction file to its sections, not an observed execution order. Select a section to read the source. 6 more sections are available in the original file.

File reference map

References: 4
Files making referencesReferenced content
Lines show actual file references, not execution order. Select a node to highlight its connections and inspect the files and source locations. Dashed lines include files that still need locating.
Files and check records5 files

Coverage and gaps

Content covered in each file

These are the source ranges included in this check, not a guarantee that every issue has been resolved.

  • SKILL.mdFull text included
  • references/compliance.mdFull text included
  • references/platforms.mdFull text included
  • references/sequence-templates.mdFull text included
  • evals/evals.jsonFull text included

This report is for the version above. We read the available code and instructions without running the skill or checking extra packages it installs. This is not a promise of safety: a different version or setup may behave differently.

  • SKILL.mdInstructions
  • evals/evals.jsonSupporting file
  • references/compliance.mdSupporting file
  • references/platforms.mdSupporting file
  • references/sequence-templates.mdSupporting file
Lines read
1,245
File checksum (to compare versions)
5b7446b22430110750c72edd6a9486526c5bc36dfa39abc5991146f2eefff86a