Back to skill

Security audit

auditor-formula100k

Security checks for vulnerabilities and agentic risk

Overview

The skill performs a coherent audit workflow, but it can route client data through external services and persist business audit details without a clear opt-in or retention control.

Review this before installing if you handle client-confidential metrics or account data. Confirm where Composio, Apify, Telegram, entregables/, cerebro/memoria/, and MEMORY.md data will live, and avoid using it for sensitive audits unless you are comfortable with persistent local memory and third-party transit.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (11)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 130)May include surrounding context.

md
- Modo `skool` → leer `references/skool-dimensions.md` (12 dimensiones)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 430)May include surrounding context.

md
- Modo `skool` → leer `references/skool-dimensions.md` (12 dimensiones)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger phrases are broad enough to match ordinary requests for reviewing a community or content strategy, which can cause the skill to activate unexpectedly. Over-broad activation matters here because the skill gathers extensive inputs, may use third-party services, and stores persistent memory, so accidental invocation can expose more user/client data than intended.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill uses external services (Composio, Apify, Telegram) to collect and transmit audit inputs, but this data flow is not clearly reflected in the top-level purpose/manifest. That creates a transparency and consent gap: users may provide client data for an 'audit' without realizing it will be sent through third-party systems, increasing privacy and compliance risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill tells the agent to store what would normally be transient working memory into cerebro/memoria/, but the description does not warn users that client audit data will be retained. This omission undermines informed consent and can lead to unexpected storage of sensitive commercial, performance, or customer information.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The description specifies delivery in 'español neutro', and the later tone section makes this non-negotiable. This is a natural-language locale constraint imposed by the skill without offering the user a choice or documenting a justified regional requirement.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill persists longitudinal client memory and updates a global index, even though the manifest primarily promises three output artifacts. This hidden persistence can store sensitive business information beyond the immediate task, creating unexpected retention, cross-session exposure, and possible leakage into future prompts or unrelated workflows.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction 'NUNCA argentino' is an explicit locale policy that forces one Spanish variant and bans another regardless of user preference. This is a natural-language policy violation because it removes language choice rather than adapting to the user's locale or opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file’s title and operative instruction are entirely in Spanish, including the directive 'Usar cuando modo = skool', which implies this reference is to be used in that mode by default. There is no indication that users may choose another language or that the Spanish-only constraint is required for a region-specific purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

El contenido está redactado íntegramente en español y además instruye 'Usar cuando modo = contenido', lo que sugiere un comportamiento predeterminado en ese idioma. No se ofrece una opción de idioma ni una justificación de que la skill sea específicamente regional, lo que encaja con una posible violación de política de idioma/locale.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill embeds an explicit shell command (mkdir -p) for file-system manipulation. Even though the command itself is simple and not obviously destructive, instructing an agent to invoke shell/system capabilities expands the skill's authority beyond pure content generation and creates a path for command execution patterns to spread into runtime behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.