Back to skill

Security audit

auditor-ganchos-cuenta-formula100k

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Spanish workflow for auditing Instagram/TikTok reels, with expected third-party services and report files but privacy and retention choices users should approve.

Install only if you are comfortable sending social-media account data, transcripts, captions, media URLs, generated images, and any pasted first-party analytics to the named external services. Before running it, confirm costs, which providers will be used, whether data will be retained locally, and whether optional memory, Segundo Cerebro, or Yapper actions should be enabled.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (14)

Credential Access

High
Category
Privilege Escalation
Content
anatomia/WINNERS_anatomy.png anatomía por segundos (frames 0/3/6/10s apilados)
anatomia/LOSERS_anatomy.png
layouts-editores/1..6.png    layouts de gancho Higgsfield (9:16, 2k) para editores
carrier/blind_NN.png+.txt    frames barajados + mapping_SECRET.json (lectura ciega del carrier)
carrier/carrier.json         carrier codificado × grupo + medianas (dato para el reporte y el HTML)
REPORTE.md                   reporte markdown completo
CALENDARIO_GUIONES.md        (opcional) semana de guiones con el criterio ganador
Confidence
70% confidence
Finding
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Credential Access

High
Category
Privilege Escalation
Content
anatomia/WINNERS_anatomy.png anatomía por segundos (frames 0/3/6/10s apilados)
anatomia/LOSERS_anatomy.png
layouts-editores/1..6.png    layouts de gancho Higgsfield (9:16, 2k) para editores
carrier/blind_NN.png+.txt    frames barajados + mapping_SECRET.json (lectura ciega del carrier)
carrier/carrier.json         carrier codificado × grupo + medianas (dato para el reporte y el HTML)
REPORTE.md                   reporte markdown completo
CALENDARIO_GUIONES.md        (opcional) semana de guiones con el criterio ganador
Confidence
70% confidence
Finding
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Credential Access

High
Category
Privilege Escalation
Content
anatomia/WINNERS_anatomy.png anatomía por segundos (frames 0/3/6/10s apilados)
anatomia/LOSERS_anatomy.png
layouts-editores/1..6.png    layouts de gancho Higgsfield (9:16, 2k) para editores
carrier/blind_NN.png+.txt    frames barajados + mapping_SECRET.json (lectura ciega del carrier)
carrier/carrier.json         carrier codificado × grupo + medianas (dato para el reporte y el HTML)
REPORTE.md                   reporte markdown completo
CALENDARIO_GUIONES.md        (opcional) semana de guiones con el criterio ganador
Confidence
70% confidence
Finding
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Credential Access

High
Category
Privilege Escalation
Content
anatomia/WINNERS_anatomy.png anatomía por segundos (frames 0/3/6/10s apilados)
anatomia/LOSERS_anatomy.png
layouts-editores/1..6.png    layouts de gancho Higgsfield (9:16, 2k) para editores
carrier/blind_NN.png+.txt    frames barajados + mapping_SECRET.json (lectura ciega del carrier)
carrier/carrier.json         carrier codificado × grupo + medianas (dato para el reporte y el HTML)
REPORTE.md                   reporte markdown completo
CALENDARIO_GUIONES.md        (opcional) semana de guiones con el criterio ganador
Confidence
70% confidence
Finding
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Ae1

High
Category
analysis-evasion
Content
- `references/prompts-higgsfield.md` — 12 plantillas de prompt para mockups por categoría
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Vague Triggers

Medium
Confidence
91% confidence
Finding
The activation phrases are broad enough to match ordinary requests about analyzing an account, which can cause the skill to trigger unexpectedly and launch scraping/report-generation workflows. In this skill, unintended activation is more sensitive because the workflow sends data to multiple external services and incurs cost.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill uses several external services (Apify, Higgsfield, Composio, Telegram, Yapper) without a consolidated disclosure or consent step. Because the workflow moves content and analytics across multiple vendors, the context makes this more dangerous than a typical formatting skill: the user may not realize how broadly their data is being shared.

Intent-Code Divergence

Medium
Confidence
96% confidence
Finding
Lines L070-L076 list artifacts such as downloaded MP4 reels and frames at t=1s, implying a video-download and ffmpeg-based workflow. That directly conflicts with the OpenClaw/server-specific instructions at L014-L018, L153-L154, and L423 stating no video downloads and no ffmpeg on this server, making the documentation internally contradictory.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill directs the agent to scrape Instagram/TikTok data via Apify and optionally combine it with native statistics, but it does not require a clear user-facing disclosure that account identifiers, transcripts, captions, and media URLs will be sent to a third party. That creates a privacy and consent risk, especially when analyzing third-party accounts or mixing in first-party analytics.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The file’s natural-language instructions and embedded HTML explicitly fix the document language to Spanish, including `<html lang="es">` and all required UI copy in Spanish. This is a language/locale policy concern because the template mandates a single language without any opt-in, alternative locale, or stated regional justification.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The 'Reglas comunes' section hard-codes Spanish-oriented requirements such as minimum resolution because long Spanish text must render well and explicitly instructs users to write accented Spanish words. This is a natural-language locale constraint presented as a default rule, with no user opt-in or explanation that the skill is intended only for Spanish-language content.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The template explicitly instructs generation and storage of raw datasets, downloaded reel videos, screenshots, and report artifacts, but includes no guidance on consent, retention limits, access control, or lawful handling of third-party social media content. In a skill that audits identifiable accounts and aggregates media/transcripts, this omission can normalize unnecessary collection and persistence of personal or copyrighted data, increasing privacy, compliance, and misuse risk.

Intent-Code Divergence

Low
Confidence
89% confidence
Finding
L388 says to confirm that the HTML is open, suggesting a local-open workflow. But L375-L378 explicitly replace opening with compressing the folder and sending the ZIP in this agent, so the user-facing instruction contradicts the actual execution context.

Natural-Language Policy Violations

Low
Confidence
96% confidence
Finding
The instruction requires "español neutro en TODO output" and forbids alternative variants such as voseo, which enforces a locale/language style choice regardless of user preference. This is a natural-language policy issue because it does not offer the user a language or locale choice or document user consent.

Static analysis

No suspicious patterns detected.