Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md - Modo `skool` → leer `references/skool-dimensions.md` (12 dimensiones)
Security audit
Security checks for vulnerabilities and agentic risk
The skill performs a coherent audit workflow, but it can route client data through external services and persist business audit details without a clear opt-in or retention control.
Review this before installing if you handle client-confidential metrics or account data. Confirm where Composio, Apify, Telegram, entregables/, cerebro/memoria/, and MEMORY.md data will live, and avoid using it for sensitive audits unless you are comfortable with persistent local memory and third-party transit.
Referenced artifact was not completely inspected
- Modo `skool` → leer `references/skool-dimensions.md` (12 dimensiones)
Referenced artifact was not completely inspected
- Modo `skool` → leer `references/skool-dimensions.md` (12 dimensiones)
The trigger phrases are broad enough to match ordinary requests for reviewing a community or content strategy, which can cause the skill to activate unexpectedly. Over-broad activation matters here because the skill gathers extensive inputs, may use third-party services, and stores persistent memory, so accidental invocation can expose more user/client data than intended.
The skill uses external services (Composio, Apify, Telegram) to collect and transmit audit inputs, but this data flow is not clearly reflected in the top-level purpose/manifest. That creates a transparency and consent gap: users may provide client data for an 'audit' without realizing it will be sent through third-party systems, increasing privacy and compliance risk.
The skill tells the agent to store what would normally be transient working memory into cerebro/memoria/, but the description does not warn users that client audit data will be retained. This omission undermines informed consent and can lead to unexpected storage of sensitive commercial, performance, or customer information.
The description specifies delivery in 'español neutro', and the later tone section makes this non-negotiable. This is a natural-language locale constraint imposed by the skill without offering the user a choice or documenting a justified regional requirement.
The skill persists longitudinal client memory and updates a global index, even though the manifest primarily promises three output artifacts. This hidden persistence can store sensitive business information beyond the immediate task, creating unexpected retention, cross-session exposure, and possible leakage into future prompts or unrelated workflows.
The instruction 'NUNCA argentino' is an explicit locale policy that forces one Spanish variant and bans another regardless of user preference. This is a natural-language policy violation because it removes language choice rather than adapting to the user's locale or opt-in.
The file’s title and operative instruction are entirely in Spanish, including the directive 'Usar cuando modo = skool', which implies this reference is to be used in that mode by default. There is no indication that users may choose another language or that the Spanish-only constraint is required for a region-specific purpose.
El contenido está redactado íntegramente en español y además instruye 'Usar cuando modo = contenido', lo que sugiere un comportamiento predeterminado en ese idioma. No se ofrece una opción de idioma ni una justificación de que la skill sea específicamente regional, lo que encaja con una posible violación de política de idioma/locale.
The skill embeds an explicit shell command (mkdir -p) for file-system manipulation. Even though the command itself is simple and not obviously destructive, instructing an agent to invoke shell/system capabilities expands the skill's authority beyond pure content generation and creates a path for command execution patterns to spread into runtime behavior.
No suspicious patterns detected.