Back to skill

Security audit

SEO Afiliate guide

Security checks for vulnerabilities and agentic risk

Overview

This is a Spanish SEO affiliate-writing skill with no local execution behavior, but it tells agents to fake hands-on product testing in commercial reviews.

Review this skill before installing if you plan to publish commercial content. Remove or override the instruction to pretend products were tested, require citations or verification for prices, ratings, availability, and specifications, and only use first-person experience claims when the user supplies real test notes.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

other

Warning
Location
SKILL.md:140
Finding
Fabricated First-Hand Product Testing and Unsupported Evidence Claims## Vulnerability Details **File Location**: `SKILL.md:140`; corroborating templates at `references/ejemplos-reviews.md:56,127` and `references/estructura-detallada.md:33` **Vulnerability Type**: Deceptive Content Generation **Risk Level**: Medium ### Complete Vulnerable Snippets `SKILL.md:140`: ```markdown - **Experiencia**: Escribe como si hubieras probado el producto. Usa frases como "tras probarlo durante 3 semanas" o "en nuestra prueba de rendimiento" ``` `references/ejemplos-reviews.md:56`: ```markdown Si el Dyson se escapa de presupuesto, el Rowenta X-Force Flex 14.60 es la alternativa más sólida del mercado por la mitad del precio. Ofrece una succión excelente para el uso cotidiano y su brazo flexible es uno de los mejores que hemos probado para limpiar debajo de los muebles sin agacharse. ``` `references/ejemplos-reviews.md:127`: ```markdown - "Tras X semanas de uso, podemos confirmar que…" ``` `references/estructura-detallada.md:33`: ```markdown > Elegir una aspiradora sin cable puede ser frustrante. Hay decenas de modelos en el mercado, las fichas técnicas son confusas y las reviews en Amazon no siempre son fiables. Para ahorrarte horas de investigación, hemos analizado más de 20 modelos y seleccionado los 8 mejores según potencia de succión, autonomía real y facilidad de uso. Tanto si buscas el modelo más completo como el más económico, aquí encontrarás tu respuesta. ``` ### Technical Analysis The skill explicitly directs the agent to write as though it had personally tested a product, including claims about a three-week trial or an internal performance test. Supporting templates reinforce this behavior with statements that products were tested or that more than twenty models were analyzed. These instructions can cause simulated or nonexistent experience to be represented as genuine first-hand evidence. This conflicts with the skill's separate direction to use real data and avoid invented c ...[truncated 1849 chars]
Remediation
## Remediation Suggestions 1. Replace the instruction to “write as if” a product was tested with an explicit prohibition against claiming unperformed testing or personal use. 2. Permit first-person experience statements only when the user supplies genuine, attributable test notes or other verifiable evidence. 3. Require research-based assessments to be labeled clearly, such as “Based on manufacturer specifications and cited customer feedback.” 4. Require citations or `[VERIFY]` placeholders for prices, availability, specifications, warranties, ratings, and review counts. 5. Remove unsupported first-person claims and concrete metrics from reusable examples, or mark them prominently as fictional placeholders. 6. Add a pre-publication verification checklist covering factual claims, source dates, affiliate disclosures, and evidence for personal-experience statements. 7. Instruct the agent to distinguish manufacturer claims, third-party test results, customer opinions, and the publisher's own verified observations. 8. Fail safely when evidence is unavailable: use neutral wording and disclose that the product was not personally tested rather than inferring experience.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Vague Triggers

High
Confidence
95% confidence
Finding
The activation description is overly broad ('úsala siempre' plus many generic phrases like comparativa, review seo, mejor [producto]), which can cause the skill to trigger for loosely related requests. Over-triggering increases the chance that the agent applies persuasive affiliate-writing behavior in contexts where the user did not ask for monetized SEO content, leading to scope hijacking and reduced user control.

Ae1

High
Category
analysis-evasion
Content
> Lee `references/estructura-detallada.md` para las instrucciones exactas de cada sección.
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
> Lee `references/estructura-detallada.md` para las instrucciones exactas de cada sección.
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Intent-Code Divergence

High
Confidence
98% confidence
Finding
The skill explicitly instructs the model to write as if it had personally tested products, using phrases like 'tras probarlo durante 3 semanas,' without requiring any real-world verification. This encourages fabrication of first-hand experience and deceptive trust signals, which can materially mislead users making purchase decisions and create legal, reputational, and consumer-protection risk.

Natural-Language Policy Violations

Medium
Confidence
98% confidence
Finding
La descripción indica que el skill crea contenido "en español" como comportamiento por defecto, pero no ofrece alternativa ni opt-in del usuario para idioma o locale. Según la política, forzar un idioma específico sin elección explícita constituye una violación de política lingüística.

Ssd 4

Medium
Confidence
97% confidence
Finding
The instruction to simulate first-hand product experience creates a deceptive narrative sequence intended to boost credibility and conversion. In the context of affiliate content, this is especially risky because fabricated experiential claims can manipulate purchasing decisions, undermine content integrity, and expose operators to platform-policy and advertising-compliance violations.

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
This file presents all instructions, labels, and examples only in Spanish, which can constitute a language-policy violation when no user opt-in or alternative locale is offered. The content does not state that it is intended specifically for a Spanish-speaking or region-specific audience.

Natural-Language Policy Violations

Low
Confidence
86% confidence
Finding
This markdown file contains user-facing instructional content exclusively in Spanish, and there is no indication that the skill is intentionally limited to Spanish-speaking users or that users can opt into the locale. Under the language/locale policy rule, forcing a specific language without opt-in can be a policy concern.

Static analysis

No suspicious patterns detected.