Back to skill

Security audit

auditor-ux-app-f100k

Security checks for vulnerabilities and agentic risk

Overview

This is mostly a disclosed UX-audit skill, but it includes under-scoped instructions that could create or use bypass-style access paths during an audit.

Review before installing. Require explicit user approval before any route creation, source edits, localStorage injection for gated flows, push, or deploy. Prefer test accounts and existing local-only preview fixtures, and use this only on repositories you trust to run locally.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
references/recorrido-navegador.md:15
Finding

Audit instructions permit unapproved creation of an unauthenticated preview route

Content
View full analysis

Vulnerability Details

File Location: references/recorrido-navegador.md:15-20
Vulnerability Type: Unauthorized source modification and access-control weakening
Risk Level: Medium

Vulnerable Instruction

markdown
2. **¿Necesita variables de entorno?** Si faltan y la app no arranca, no inventes: audita el código y anota
   en "No verificado" que el recorrido no se pudo hacer y por qué.
3. **Si la app exige login y no lo tienes**, busca (o crea, si es barato) una ruta de previsualización que
   renderice el shell con datos falsos. En una de las apps de origen existía una ruta así y es lo que permitió medir el menú
   móvil sin sesión. Es la forma honesta de auditar el layout sin credenciales.

Technical Analysis

When an application requires authentication and the auditor lacks credentials, the instructions authorize the agent to create a preview route based only on whether doing so is “cheap.” This is an instruction to modify the audited repository during the audit phase.

That behavior conflicts with the Skill’s own approval boundary in SKILL.md, which requires the agent to stop after producing the report and wait for approval before editing files. The preview-route instruction contains no equivalent approval requirement, local-only restriction, production-build exclusion, or technical control preventing the route from accessing real application services.

Although the stated purpose is legitimate UX inspection using synthetic data, the instruction creates a reachable path for an agent to make an access-control-sensitive source change without the repository owner’s explicit approval. There is no evidence that the Skill author intends to create a backdoor, so this is classified as suspicious rather than malicious.

Attack Path

  1. A user requests a UX audit of a repository containing an authenticated application.
  2. The user does not provide test credentials.
  3. The agent follows references/recorrido-navegador.md:18-20.
  4. I ...[truncated 1266 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the instruction to create a preview route during the audit phase.
  2. If no existing preview route or test credentials are available, require the agent to record the authenticated browser flow as “Not verified.”
  3. Permit creation of a preview mechanism only after explicit user approval at the Phase 4 checkpoint.
  4. Require any approved preview mechanism to:
    • Bind only to the local development environment.
    • Be excluded from production builds.
    • Use synthetic data exclusively.
    • Avoid production databases, sessions, APIs, and secrets.
    • Fail closed when the environment is not explicitly marked as development or test.
  5. Require the agent to list every modified file and remove the preview mechanism after testing unless the user expressly requests that it remain.
  6. Add an explicit instruction such as:
markdown
Do not create or modify routes during the audit. If no existing safe preview route or test account is
available, mark authenticated browser coverage as “Not verified.” A local-only preview route may be
created only after the user explicitly approves the application plan.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 96)May include surrounding context.

md
el arreglo típico. Mientras la recorres, cruza contra `references/cicatrices-produccion.md`: son los

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 162)May include surrounding context.

md
el arreglo típico. Mientras la recorres, cruza contra `references/cicatrices-produccion.md`: son los

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 192)May include surrounding context.

md
el arreglo típico. Mientras la recorres, cruza contra `references/cicatrices-produccion.md`: son los

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

La instrucción "Español neutro en todo lo que la usuaria vea" fuerza una política de idioma para salidas de la skill. Según la política, imponer un idioma o variante regional sin opción del usuario constituye una violación de política lingüística, salvo que esté claramente justificada como restricción regional, lo que aquí no se documenta.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Todo el contenido operativo e instructivo del archivo está únicamente en español y no ofrece elección de idioma ni indica que sea una guía limitada a un contexto regional o lingüístico específico. Según la política, forzar un idioma sin opt-in o justificación documentada constituye una violación de política de lenguaje/locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction "Todas en español neutro" imposes a specific language for all templates. This is a natural-language locale policy constraint, and the file does not offer user opt-in, alternatives, or a documented region-specific justification.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The skill instructs the agent to start the target application locally using package-manager commands, expanding its behavior from passive UX review into code execution against an untrusted workspace. Running repo-defined scripts can execute arbitrary preinstall/dev tooling, expose local secrets, or modify the environment, so this creates a real attack surface even if the stated goal is only to inspect the app.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill tells the agent to inject synthetic state into localStorage to bypass paid or gated flows and reach otherwise inaccessible screens. Even when framed as UX testing, this normalizes tampering with authorization or monetization gates and can lead the agent to access states that should require payment, credentials, or server-side validation assumptions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Line L217 states that all visible text must be in 'español neutro' and forbids other variants, which is a language policy constraint expressed as a universal requirement. Because the file does not present this as an optional preference or a justified region-specific limitation, it constitutes a natural-language locale policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.