Back to skill

Security audit

audios-venta-f100k

Security checks for vulnerabilities and agentic risk

Overview

This is a text-only skill for drafting Spanish sales voice-message scripts, with disclosed local draft storage and no evidence of hidden execution or sending behavior.

Install only if you want an OpenClaw skill that drafts Spanish sales voice-message scripts and stores them as local deliverable Markdown files. Review any prospect or business data it pulls from your local cerebro/ context before using the generated script, and adjust the dialect or tone if your audience is not best served by neutral Spanish.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 152)May include surrounding context.

md
Las 6 plantillas completas de audio (con guion palabra por palabra y notas de entrega) están en [templates.md](templates.md).

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

La cláusula de activación 'o cualquier variación que combine vender + formato hablado privado 1-on-1' es demasiado abierta y puede disparar la skill fuera de su ámbito previsto. Eso crea riesgo de selección errónea de herramienta, respuestas no deseadas y bypass de skills más específicas o seguras para tareas cercanas.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Forzar 'español neutro (NO argentino)' sin opt-in del usuario impone una preferencia lingüística rígida que puede contradecir el contexto conversacional o la voz de marca del usuario. Aunque no es una vulnerabilidad de seguridad clásica, sí puede causar salidas inapropiadas, degradación de calidad y activación de comportamiento no alineado con la intención real del usuario.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

La regla absoluta 'Español neutro siempre' refuerza una restricción inflexible de idioma/variante que puede entrar en conflicto con instrucciones superiores del usuario o con necesidades del caso. En un sistema multi-skill, este tipo de rigidez aumenta el riesgo de respuestas incorrectas o poco usables, aunque su impacto de seguridad es limitado.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The checklist explicitly requires 'Español neutro', which imposes a language constraint in the skill's natural-language instructions. There is no indication that the user can choose another language or that the Spanish-only requirement is justified by a documented regional scope.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.