跳转到正文
报告库
用途分类 / 文档处理

Lead Magnets Skill 安全审计

作者说它能做什么(原文)

When the user wants to create, plan, or optimize a lead magnet for email capture or lead generation. Also use when the user mentions "lead magnet," "gated content," "content upgrade," "downloadable," "ebook," "cheat sheet," "checklist," "template download," "opt-in," "freebie," "PDF download," "resource library," "content offer," "email capture content," "Notion template," "spreadsheet template,"

第三方安全检查结论

发现安全风险

已检查文件
4
发现的风险
4
会不会运行危险命令?检查是否下载程序后直接运行、让他人远程控制电脑,或藏起要运行的命令。未发现风险
会不会泄露文件和密钥?检查是否发送含密码或密钥的文件,以及代码里是否直接写了密钥。发现 2 项风险
中风险

营销上下文文件会被自动读取并影响输出

原文依据:1 处
发现了什么

Skill 明确要求先读取三个约定路径之一的产品营销文件。此类文件可能包含未公开的客户画像、定位、指标或商业计划;指令没有要求在回答中区分可公开与机密内容。

为什么需要注意

如果请求来自外部协作者,或生成结果会进入共享文档,内部策略可能被直接引用、概括或间接暴露。

这段证据能说明什么

该指令确实要求在规划前读取并使用约定路径中的产品营销资料,因此回答可能受内部客户、定位或指标影响。但源码没有要求披露、上传或公开这些资料,读取也与营销规划目的相关。风险取决于文件是否含机密信息以及模型是否在输出中复述它们。用户可限制这些路径的访问,或要求作者增加读取确认和敏感信息过滤。

这项判断针对展示的代码和适用条件,不表示风险已经实际发生。
SKILL.md:14来自说明文档打开原文件
**Check for product marketing context first:**If `.agents/product-marketing.md` exists (or `.claude/product-marketing.md`, or the legacy `product-marketing-context.md` filename, in older setups), read it before asking questions. Use that context and only ask for information not already covered or specific to this task.
中风险

建议收集并持续使用潜在客户数据,但未要求隐私告知或同意

原文依据:6 处
发现了什么

Skill 建议收集邮箱、姓名、公司和职位,用邮件启动关系,并按测验结果定制后续邮件;这些是持续处理个人及职业信息的具体流程。现有指令只关注转化摩擦,没有要求说明用途、保存期限、退订机制或适用的营销同意。

为什么需要注意

照此上线可能造成未经预期的营销联系、过度画像,以及隐私投诉、邮件平台处罚或监管风险。

该 Skill 建议收集邮箱及职业身份字段、通过邮件投递并按测验结果定制后续邮件。这会在实际部署时处理可识别的联系人数据。虽然文案示例提到“可随时退订”,但没有要求在收集前说明用途、同意依据、保存期限或数据共享。用户可要求作者加入明确的隐私告知、营销同意、退订和最小化保存规则,并仅启用业务确需的字段。

SKILL.md:136来自说明文档打开原文件
- **Email only** — highest conversion, lowest friction- **Email + name** — enables personalization, slight friction increase- **Email + company/role** — better lead qualification, more friction- **Multi-field** — only for high-value offers (webinars, demos)Rule of thumb: Ask for the minimum needed. Every extra field reduces conversion by 5-10%.
查看另外 5 个位置
SKILL.md:172来自说明文档打开原文件
|--------|------|------|| **Instant download** | Immediate gratification | No email verification || **Email delivery** | Verifies email, starts relationship | Slight delay || **Thank you page + email** | Best of both—instant access + email copy | Slightly more complex || **Drip delivery** | Builds habit, multiple touchpoints | Only for courses/series |
references/format-guide.md:166来自说明文档打开原文件
**Result Segmentation**:- 3-5 result categories- Each result: name, description, personalized recommendations- Tailor follow-up emails by result type- Share-worthy result format ("I got: Growth Stage Marketer!")**Implementation**: Gate results behind email capture. The quiz itself is ungated — the personalized results require an email.
SKILL.md:134来自说明文档打开原文件
### What to Ask For- **Email only** — highest conversion, lowest friction- **Email + name** — enables personalization, slight friction increase- **Email + company/role** — better lead qualification, more friction- **Multi-field** — only for high-value offers (webinars, demos)Rule of thumb: Ask for the minimum needed. Every extra field reduces conversion by 5-10%.
SKILL.md:168来自说明文档打开原文件
### Delivery Methods| Method | Pros | Cons ||--------|------|------|| **Instant download** | Immediate gratification | No email verification || **Email delivery** | Verifies email, starts relationship | Slight delay || **Thank you page + email** | Best of both—instant access + email copy | Slightly more complex || **Drip delivery** | Builds habit, multiple touchpoints | Only for courses/series |
SKILL.md:145来自说明文档打开原文件
- Make the value obvious: "Get the full 25-page guide free"- Show a preview: table of contents, first page, sample results- Add social proof: "Downloaded by 5,000+ marketers"- Reduce risk: "No spam. Unsubscribe anytime."
会不会删除文件或一直在后台运行?检查是否大范围删除文件、改写磁盘,或设置自动启动。未发现风险
会不会绕过安全保护?检查是否跳过网站安全验证、开放过多文件权限,或取消操作前的确认。未发现风险
会不会误导 AI 或隐藏内容?检查工作说明是否要求 AI 忽略你的指令、干扰检查结果,或夹带看不见的文字。未发现风险
会不会偷偷改推广链接或收款方?检查是否强制替换推广链接或收款对象,同时要求隐瞒更改。发现 2 项风险
中风险

示例可能诱导发布未经证实的下载量社会证明

原文依据:1 处
发现了什么

Skill 直接把“Downloaded by 5,000+ marketers”列为应添加的社会证明,却没有要求核实该数字或把它标记为占位符。

为什么需要注意

若用户照搬而实际没有相应下载记录,落地页会作出虚假营销陈述,可能损害客户信任并带来广告平台、消费者保护或合同风险。

“Downloaded by 5,000+ marketers”位于营销文案示例中,并非声称某个真实产品已有该下载量;但它被直接列为应添加的社会证明,且没有“仅在可验证时使用”或占位符说明。如果模型把示例原样用于真实页面,用户可能发布误导性声明并损害客户信任。用户可要求作者规定所有数量型社会证明必须有可核验记录,否则改用不含数字的真实证明。

SKILL.md:143来自说明文档打开原文件
### How to Frame the Exchange- Make the value obvious: "Get the full 25-page guide free"- Show a preview: table of contents, first page, sample results- Add social proof: "Downloaded by 5,000+ marketers"- Reduce risk: "No spam. Unsubscribe anytime."
低风险

转化率、成本和每字段影响数字没有注明来源

原文依据:6 处
发现了什么

Skill 提供行业转化率、渠道成本以及“每增加字段降低 5–10%”等具体数字,但没有给出数据来源、样本、日期或统计口径。参考文件最后承认这些只是通用指南。

为什么需要注意

若将这些数字当成承诺或可靠行业基线,用户可能设置不现实的目标、错误评价活动,或在付费渠道上分配不当预算。

源码给出了每增加字段降低转化率、行业转化率和渠道获客成本等具体区间,却未提供研究来源、采样时间或口径。参考文件末尾明确称它们只是通用指南,这降低了确定性,但主 Skill 仍可能让用户把数字当成可靠基准作预算或表单决策。用户可要求作者补充出处和日期,并把这些范围仅作为假设,以自己的数据验证。

SKILL.md:136来自说明文档打开原文件
- **Email only** — highest conversion, lowest friction- **Email + name** — enables personalization, slight friction increase- **Email + company/role** — better lead qualification, more friction- **Multi-field** — only for high-value offers (webinars, demos)Rule of thumb: Ask for the minimum needed. Every extra field reduces conversion by 5-10%.
查看另外 5 个位置
SKILL.md:229来自说明文档打开原文件
| Metric | What It Tells You | Benchmark ||--------|-------------------|-----------|| **Landing page conversion rate** | Offer attractiveness | 20-40% (warm traffic), 5-15% (cold) || **Cost per lead** | Acquisition efficiency | Varies by channel and industry || **Lead-to-customer rate** | Lead quality | 1-5% (B2B), varies widely || **Email engagement** | Content relevance | 30-50% open, 2-5% click || **Time to conversion** | Nurture effectiveness | Track by lead magnet source |
references/benchmarks.md:80来自说明文档打开原文件
| Channel | Typical CPL | Notes ||---------|-------------|-------|| Organic search | $0-5 | Lowest, but slow to build || Blog content upgrade | $0-2 | Nearly free if you have traffic || Facebook/Instagram Ads | $3-15 | B2C lower, B2B higher || Google Ads | $10-50 | High intent, higher cost || LinkedIn Ads | $25-75 | B2B, expensive but qualified || Partner co-promotion | $0-5 | Depends on relationship |
references/benchmarks.md:129来自说明文档打开原文件
**Note**: These benchmarks are general guidelines. Your actual results depend on audience, niche, traffic volume, and offer quality. Start measuring from day one and build your own benchmarks.
references/benchmarks.md:33来自说明文档打开原文件
### By Industry (Landing Page)| Industry | Average Conversion ||----------|-------------------|| SaaS/Tech | 15-25% || Marketing/Agency | 20-35% || Finance | 10-20% || E-commerce | 10-20% || Education | 20-35% || Health/Wellness | 15-25% |
references/benchmarks.md:78来自说明文档打开原文件
### Cost Per Lead by Channel| Channel | Typical CPL | Notes ||---------|-------------|-------|| Organic search | $0-5 | Lowest, but slow to build || Blog content upgrade | $0-2 | Nearly free if you have traffic || Facebook/Instagram Ads | $3-15 | B2C lower, B2B higher || Google Ads | $10-50 | High intent, higher cost || LinkedIn Ads | $25-75 | B2B, expensive but qualified || Partner co-promotion | $0-5 | Depends on relationship |

Skill 逻辑拆解

8 个说明模块

这是一个营销策略指导型 Skill,主要输出铅磁铁的内容、表单、分发和衡量方案。所提供的完整源文件中没有脚本、安装命令、凭据请求或直接网络调用。

查看原文
SKILL.md:260来自说明文档打开原文件
When creating a lead magnet strategy, provide:### 1. Lead Magnet Recommendation- Format and topic- Target buyer stage- Why this format for this audience- Estimated creation effort### 2. Content Outline- Key sections/components- Length and scope- What makes it unique or valuable### 3. Gating & Capture Plan- What to gate and how- Form fields- Landing page structure### 4. Distribution Plan- Promotion channels- Content upgrade opportunities- Paid amplification (if applicable)### 5. Measurement Plan- KPIs and targets- What to A/B test first

运行时会先查找并读取项目中的产品营销上下文文件,再用其中的信息减少提问并制定建议。

查看原文
SKILL.md:14来自说明文档打开原文件
**Check for product marketing context first:**If `.agents/product-marketing.md` exists (or `.claude/product-marketing.md`, or the legacy `product-marketing-context.md` filename, in older setups), read it before asking questions. Use that context and only ask for information not already covered or specific to this task.

它建议用表单收集邮箱及可选的姓名、公司和职位信息,并通过邮件、滴灌课程及按测验结果细分的后续邮件持续营销。

查看原文
SKILL.md:134来自说明文档打开原文件
### What to Ask For- **Email only** — highest conversion, lowest friction- **Email + name** — enables personalization, slight friction increase- **Email + company/role** — better lead qualification, more friction- **Multi-field** — only for high-value offers (webinars, demos)Rule of thumb: Ask for the minimum needed. Every extra field reduces conversion by 5-10%.
references/format-guide.md:166来自说明文档打开原文件
**Result Segmentation**:- 3-5 result categories- Each result: name, description, personalized recommendations- Tailor follow-up emails by result type- Share-worthy result format ("I got: Growth Stage Marketer!")**Implementation**: Gate results behind email capture. The quiz itself is ungated — the personalized results require an email.

评测文件是测试期望而非运行实现;它要求模型复述特定营销判断和数字,但没有增加执行能力。

查看原文
evals/evals.json:34来自说明文档打开原文件
      "id": 3,      "prompt": "Our lead form asks for name, email, company, role, company size, and phone. We're not getting enough signups. Could the form be the problem?",      "expected_output": "Should immediately flag form length as a likely culprit. Should cite the rule of thumb: every extra field reduces conversion 5-10%. Should recommend reducing to the minimum needed: ideally email only (highest conversion), or email + name if personalization matters. Should explain when multi-field is justified (only for high-value offers like webinars or demos). Should ask what information is actually used in follow-up — fields that aren't used should be removed. Should suggest progressive profiling: capture email now, ask for more fields later via enrichment or follow-up forms. Should reference cro skill for form optimization specifically.",      "assertions": [        "Flags form length as likely culprit",        "Cites 5-10% per field rule",        "Recommends reducing to email or email + name",        "Asks what fields are actually used",        "Suggests progressive profiling",        "Cross-references cro skill"      ],
从这里开始 · 工作说明SKILL.md
lead-magnets
连线表示工作说明包含的模块,不是实际运行顺序。点击模块可查看原文。 另有 3 个章节,可在原文件中查看。

文件引用关系图

2 处引用
哪些文件发起引用引用了什么
连线表示真实的文件引用,不是运行顺序。点击节点可高亮相关连线,并查看具体文件和原文位置。虚线表示还有文件需要定位。
文件与检查记录4 个文件

检查范围与遗漏

逐文件查看涉及的内容

下方列出本次涉及的原文范围;纳入检查不代表已查清所有问题。

  • SKILL.md已纳入全文
  • references/benchmarks.md已纳入全文
  • references/format-guide.md已纳入全文
  • evals/evals.json已纳入全文

这份报告只针对上方版本。我们看了拿到的代码和说明文件,没有实际运行 Skill,也没有检查它另外安装的软件包。因此,这不是“保证安全”的承诺;换了版本或使用环境,结果也可能不同。

  • SKILL.md工作说明
  • evals/evals.json配套文件
  • references/benchmarks.md配套文件
  • references/format-guide.md配套文件
读取了多少行
726
文件校验值(用于核对版本)
7514f1379881e3e121824414d7f638c7a563f1dc2abe18ef991530d95aa38ab3