Skip to content

Security: whystrohm/whystrohm-audit

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

This is a Claude Code skill. It runs in your Claude Code session and does not send your data to any WhyStrohm server. It reads your website through public URLs and runs public web searches, as described below. It reads and writes one file each in a brand/ folder in your current folder, as described below.

If you discover a security concern (e.g., the skill could be manipulated to execute unintended commands, or the scoring rubric contains logic that could be exploited):

Email: hello@whystrohm.com

Please include:

  • Description of the concern
  • Steps to reproduce
  • Potential impact

We will respond within 48 hours.

Scope

This skill has no backend, no database, and no authentication. It makes these network calls, all through Claude Code's own tools:

  • WebFetch of the website URL you provide (homepage, about or services page, and a recent blog post if one exists).
  • WebSearch for how your named buyer talks about the problem (Step 4b). The search query is built from your answers to the buyer and differentiator questions.
  • WebFetch of 1-2 public pages from those search results, such as review sites, forum threads, or video pages.

Compliant sources only. The skill reads public pages and search results. It never scrapes authenticated or walled platforms (LinkedIn, X/Twitter, Instagram) behind a login or with cookies.

Local files, in the folder you run it from:

  • Reads brand/voice-profile.json if it is there (written by whystrohm-voice-extract). It is used as the website voice baseline for Voice Consistency, and only if its contract, version, host and six dimensions check out.
  • Writes brand/audit-findings.json at the end of the audit: the scores, quotes, gaps and rewrite you saw, plus the content sample you pasted. If the file already exists, the skill shows its URL and date and asks before replacing it. Where file access is not available, it prints the JSON instead.

It reads and writes nothing else on disk.

The attack surface is the skill's markdown instructions, how Claude Code interprets them, and the content of the public pages it reads, and the content of brand/voice-profile.json if present.

There aren't any published security advisories