Back to skill

Security audit

animacion-dibujada-f100k

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real local animation-rendering skill, but it deserves review because it can splice raw JavaScript from plan files into locally rendered pages while also handling personal photos and voice files.

Install only if you trust the project plans and media sources used with it. Do not run third-party `plan.json` files or paste untrusted `js:` values, because they can become code inside the local renderer. Treat user photos, face JSON, voice files, and `.corto-tmp` caches as personal data and delete them when the project is done.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (60)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

La descripción presenta una capacidad amplia de creación de videos/animaciones completas con múltiples estilos y flujos narrativos. En cambio, este fragmento únicamente define recursos gráficos de un kit de fitness para un motor de dibujo existente: objetos de gimnasio, un fondo de gimnasio y un registro de kit. Aunque usa canvas/JavaScript y un objeto (cronómetro) tiene animación simple, no hay lógica para componer clips, exportar video, manejar formato 9:16, generar personajes/mascotas, procesar fotos, añadir subtítulos, voz, transiciones ni operar como la herramienta descrita. Por tanto, la descripción no representa fielmente lo que este código chunk hace realmente.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

La descripción declara una capacidad amplia de creación de videos/animaciones dibujadas en JavaScript, incluyendo varios estilos de clip y un sistema de cortos con personajes, mascotas, voz y subtítulos. El código suministrado no realiza nada de eso directamente: únicamente añade recursos visuales para un dominio específico (inmobiliario) dentro de un motor mayor, mediante llamadas como registrarObjeto, registrarEscenario y registrarKit. No hay lógica de render de video, composición temporal, animación de personajes, procesamiento de fotos, audio ni subtítulos. Por tanto, la conducta observada corresponde a un kit de ilustraciones inmobiliarias y no representa fielmente la descripción declarada.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents a broad end-user skill for generating animated shorts and reel inserts entirely in JavaScript/canvas, with many styles and higher-level features such as photo-derived pets, animated characters, subtitles, transitions, and voice integration. The actual code chunk is much narrower and materially different: it only defines a jewelry-themed asset kit and scene within a larger drawing framework. While it does use canvas-style drawing primitives and supports animation for sparkles/highlights, that is merely a supporting implementation detail. Its primary purpose in this chunk is to register jewelry illustrations and a jewelry-store environment, not to provide the advertised end-user video/short creation capabilities. Therefore this code chunk does not accurately represent the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents a full animated video creation skill with many styles and end-to-end short-form rendering capabilities. The supplied code does not implement that primary purpose. It only adds a themed graphics kit consisting of canvas-drawn makeup-related objects and a studio background via registrarObjeto, registrarEscenario, and registrarKit. This is materially different from generating animated shorts, pet/person characters, subtitles, transitions, or voice-driven explainers. The code is related to a drawing/animation framework, but this chunk is specifically an asset pack for makeup scenes rather than the claimed general-purpose animated clip generator.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

La discrepancia es material. La descripción promete una herramienta amplia de creación de videos animados dibujados con código, mientras que el código suministrado únicamente registra recursos visuales estáticos o casi estáticos para un tema de nutrición dentro de un motor mayor. Aunque ambos se relacionan con dibujo en canvas/JavaScript, este fragmento no implementa la finalidad declarada ni capacidades centrales como generación de clips, personajes, mascotas desde foto, subtítulos, voz o múltiples estilos de reel. Por tanto, la descripción no representa con precisión lo que este código hace realmente.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

La descripción declara una capacidad amplia de creación de videos/cortos animados 9:16 con múltiples estilos y funciones narrativas. En cambio, este fragmento únicamente registra recursos visuales de un kit de 'pastelería' para un motor gráfico preexistente. Aunque usa canvas/JavaScript y algunos objetos tienen animación simple, eso es solo un detalle de implementación y no respalda la promesa principal del skill. La finalidad observable de este código es proveer ilustraciones y un escenario temático, no fabricar cortos animados completos ni las capacidades avanzadas descritas. Por tanto, hay una discrepancia material entre la descripción y el comportamiento real del código suministrado.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description promises a broad JavaScript/canvas animated video creation tool with 13 clip styles, animated shorts, pet/photo stylization, character puppeting, subtitles, voice, transitions, and local rendering. The supplied code chunk instead only registers graphical objects and a scenario for a psychologist/therapy environment, plus a named kit ('psicologo'). While it uses canvas-style drawing primitives and includes minor object animation hooks, its actual role is a narrow visual asset pack/supporting scene definition. That is materially different from the declared end-user purpose, so this is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

La descripción declara una capacidad amplia de creación de clips animados completos en varios estilos, incluyendo personajes, mascotas desde fotos, transiciones, subtítulos, voz y render local. El fragmento suministrado no realiza nada de eso de forma directa: únicamente registra elementos visuales y un escenario de restaurante para ser usados por otro motor. Aunque esto podría ser un componente de un sistema mayor de animación en canvas/JavaScript, este código concreto tiene un alcance mucho más estrecho y distinto: proveer assets gráficos temáticos. No se observan capacidades peligrosas o accesos a recursos no declarados; el problema es una diferencia material entre la finalidad descrita y el comportamiento real del código mostrado.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

La descripción promete una herramienta amplia para fabricar videos animados y clips explicativos dibujados con código. Sin embargo, este fragmento concreto únicamente registra dibujos vectoriales/canvas de elementos de una tienda de ropa y un escenario 'boutique' dentro de un sistema mayor. Aunque usa canvas/JavaScript y encaja como un posible componente visual de un generador animado, por sí solo su comportamiento real es el de un kit de assets temáticos, no el de la capacidad principal declarada. La diferencia es material en propósito y alcance, por lo que corresponde marcar mismatch.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

md
> - La voz de prueba de `armar-corto.mjs` usa `say` (Mac). En el servidor pide la voz grabada de la usuaria (nota de voz de Telegram → `ffmpeg` a .m4a) y úsala

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 114)May include surrounding context.

md
> - La voz de prueba de `armar-corto.mjs` usa `say` (Mac). En el servidor pide la voz grabada de la usuaria (nota de voz de Telegram → `ffmpeg` a .m4a) y úsala

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 116)May include surrounding context.

md
> - La voz de prueba de `armar-corto.mjs` usa `say` (Mac). En el servidor pide la voz grabada de la usuaria (nota de voz de Telegram → `ffmpeg` a .m4a) y úsala

Chaining Abuse

High
Category
Tool Misuse
Confidence
88% confidence
Finding

The skill instructs the agent to inspect user photos, infer physical attributes, create derived character sheets, and work with face/feature metadata across multiple scripts and files. This is a form of multi-step handling of sensitive personal data that can expand access and reuse beyond the original user request, especially when paired with file storage and potential message delivery, increasing privacy and misuse risk.

Content

Scanner excerpt · SKILL.md (reported line 86)May include surrounding context.

md
|---|---|---|
| Una foto suya y quiere una **mascota** | **Tú MIRAS la foto** (Read) y escribes su ficha: pelo (color, largo, estilo), piel, ojos, ropa, accesorios. El código NO adivina rasgos: medirlos a ciegas falla (toma la piel de una sombra, no ve el pelo largo). Pixelar la foto tampoco sirve: la cara sale borrosa e inquietante. | `nucleo/personaje.js` → `crearPersonaje(ficha, { estilo: 'vector'\|'pixel'\|'papel', alto })` |
| Una descripción («un gato naranja con delantal») | Escribes la ficha (`tipo: 'criatura'`) | igual |
| Su **propio personaje** (PNG, dibujo, logo con cara) | Lo animas como **títere**, sin redibujarlo: respira, salta, se bambolea, parpadea y abre la boca (ojos y boca de `cara.swift`, o escritos a mano en un JSON si Vision no ve cara) | `nucleo/titere.js` → `crearTitere(img, { cara })` |
| Una foto y quiere salir **ella misma** | Recorte (sticker con borde blanco) o títere con su foto real | `stickerDe(img)`, `estilos/tu-foto-sticker.html` |

Las fichas viven junto al proyecto de la persona, no en la skill. En `personajes/` solo hay ejemplos. Esquema y ejemplos: `personajes/ejemplo-*.json`.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 119)May include surrounding context.

md
`node scripts/corto.mjs guion.json corto.mp4`. Cada escena es una pieza armada. Los tiempos salen de la voz (`inicio` de cada escena),

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 123)May include surrounding context.

md
ra la escena (hasta 1,8×) para que termine a tiempo. Antes de renderizar: `node scripts/hoja-corto.mjs guion.json hoja.jpg`, y **mírala**.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 147)May include surrounding context.

md
3. **El freno automático**: `renderizar.mjs` lee el código antes de abrir Chrome. Si encuentra mano, brazo, dedo, piel, manga… sin la

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 193)May include surrounding context.

md
3. **El freno automático**: `renderizar.mjs` lee el código antes de abrir Chrome. Si encuentra mano, brazo, dedo, piel, manga… sin la

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script explicitly treats any plan value prefixed with "js:" as raw JavaScript and splices it directly into generated scene HTML/JS source. Because plan.json is treated as input data but can inject executable code into browser-rendered scene files, an attacker who controls the plan can execute arbitrary JavaScript during later rendering or preview steps, defeating the expectation of data-only configuration.

Content

No source excerpt is available for this finding.

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · scripts/renderizar.mjs (reported line 15)May include surrounding context.

js
//   node renderizar.mjs pieza.html salida.mp4 --dur 5.5       el video dura 5.5 s: si la pieza es más corta sostiene su último
//                                                             cuadro quieto; si es más larga, la corta (lo usa corto.mjs)
//   ... --dur 3 --encajar                                     si la animación no alcanza a terminar en 3 s, la acelera lo justo
//                                                             (hasta 1.8×) para que termine antes del corte; su «quieto final» se descuenta
//
// Necesita: Node 18+, ffmpeg y Google Chrome. `npm i` en la carpeta de la skill instala playwright-core.
import { createRequire } from 'node:module';

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill instructs use of external services and message delivery channels (notably Telegram and package installation) but does not declare any explicit tool scope or allowed-tools boundary. In an agent environment, missing permission scoping increases the chance the skill can invoke network-capable operations beyond what a user expects, making review and enforcement harder.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill advertises broad trigger phrases like 'pixel art', 'mi mascota', or 'hazme un personaje', which can match ordinary conversation and cause the skill to activate unexpectedly. In agent systems, over-broad activation increases the risk of accidental tool invocation, processing of personal media, or unintended file/network actions outside the user's specific intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill explicitly requests and processes real user photos, including facial features and appearance attributes, but does not define privacy handling, retention, deletion, or consent boundaries. That creates unnecessary exposure of biometric-adjacent and personal data, especially when files are stored in project directories and may later be transmitted or reused.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · nucleo/kits/veterinaria.js (reported line 26)May include surrounding context.

js
F(pEl(0, -80, 30, 27), CANELA, { sombra: 12, k: .9 });                                                                            // cabeza
  [-1, 1].forEach(s => { _g.save(); _g.translate(s * 27, -86); _g.rotate(s * .35);
    F(pSuave([[0, -10], [s * 12, -2], [s * 10, 22], [0, 26], [-s * 4, 6]], true, .8), CAFE, { sombra: s > 0 ? 0 : 99 }); _g.restore(); });   // las caídas
  F(pEl(0, -70, 16, 12), CANELA_C);                                                                                                 // hocico
  F(pEl(0, -76, 6, 4.5), TINTA_C, { linea: false }); F(pEl(-2, -77.5, 2, 1.2), '#ffffff', { linea: false });                        // trufa
  L(pSuave([[-6, -66], [0, -64], [6, -66]], false), TINTA_C, .5);
  F(pSuave([[-4, -64], [4, -64], [3, -57], [-3, -57]], true, .7), ROSA, { linea: false });                                          // lengüita

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · nucleo/kits/veterinaria.js (reported line 51)May include surrounding context.

js
L(pSuave([[-6, -66], [0, -68], [6, -66]], false), TINTA_C, .5);
  [-1, 1].forEach(s => [[-2, .6], [2, .5]].forEach(([dy, w]) => L(pLinea([[s * 12, -70 + dy], [s * 32, -72 + dy * 3]]), TINTA_C, .3)));  // bigotes
  ojito(-11, -82, 5); ojito(11, -82, 5);
  F(pRR(-18, -58, 36, 7, 3), MENTA);                                                                                                // collarcito
}, { ancho: 40, anima: true });

registrarObjeto('hueso', () => {

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · nucleo/kits/veterinaria.js (reported line 86)May include surrounding context.

js
const aro = pEl(0, -58, 40, 26);
  _g.save(); if (_modo === 'vector') { _g.strokeStyle = _tinta; _g.lineWidth = 12 + _lw * 2; _g.stroke(aro); }
  _g.strokeStyle = _reg(ROJO); _g.lineWidth = _modo === 'pixel' ? 9 : 12; _g.stroke(aro); _g.restore();
  F(pRR(-8, -40, 16, 10, 3), '#c3c8d2');                                                                                         // hebilla
  L(pLinea([[0, -30], [0, -24]]), '#c3c8d2', .7);
  F(pEl(0, -12, 13, 13), ORO, { brillo: [-8, -20, 4, 6] });
  huella(0, -12, 7, oscuro(ORO, .7));

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/corto.mjs:103