未经逐次确认读取隐藏的产品营销文件
原文依据:3 处调用该 Skill 后,只要几个预定路径之一存在,代理就被要求在提问前读取它。文件可能包含未准备交给此写作任务的定位、客户案例、收入数据或其他内部商业信息。
这些内容会进入代理处理上下文,并可能被改写进面向外部潜在客户的邮件;敏感的内部说法、客户名称或未公开指标因此可能意外泄露。
这是自动读取本地文件的实际指令:只要任一约定路径存在,代理就应在提问前读取。读取内容会进入代理处理上下文;如果文件含客户、业绩或内部定位信息,可能超出用户对单次邮件任务的预期披露范围。证据没有显示文件会上传给第三方或写回磁盘。用户可在使用前限制允许读取的路径,或要求先列出并征得确认。
**Check for product marketing context first:**If `.agents/product-marketing.md` exists (or `.claude/product-marketing.md`, or the legacy `product-marketing-context.md` filename, in older setups), read it before asking questions. Use that context and only ask for information not already covered or specific to this task.查看另外 2 个位置
1. **Who are you writing to?** — Role, company, why them specifically2. **What do you want?** — The outcome (meeting, reply, intro, demo)3. **What's the value?** — The specific problem you solve for people like them4. **What's your proof?** — A result, case study, or credibility signal5. **Any research signals?** — Funding, hiring, LinkedIn posts, company news, tech stack changes## Before Writing**Check for product marketing context first:**If `.agents/product-marketing.md` exists (or `.claude/product-marketing.md`, or the legacy `product-marketing-context.md` filename, in older setups), read it before asking questions. Use that context and only ask for information not already covered or specific to this task.