Back to skill

Security audit

autopilot-guiones-f100k

Security checks for vulnerabilities and agentic risk

Overview

The skill is mainly a content automation workflow, but it needs Review because it contradicts itself about Gmail use while also using account credentials and sending generated content to external services.

Install only if you want this skill to use the listed services for daily script delivery. Before enabling it, resolve whether Gmail drafts are actually intended, confirm the Yapper endpoint and token scope, and avoid scheduled runs until each destination is explicitly configured and understood.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

En la sección de OpenClaw se indica explícitamente que 'No hay draft de Gmail' y que los guiones llegan por Telegram y se guardan en guiones/. Sin embargo, más abajo el procedimiento define como PASO 5 'CREAR DRAFT DE GMAIL' con contenido completo del correo, lo que contradice el comportamiento declarado del skill y cambia el canal de entrega prometido.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Las notas introductorias dicen 'No hay draft de Gmail', pero el mismo archivo incluye instrucciones detalladas para crear un borrador de Gmail en las líneas posteriores. Esto no es mera omisión: es una contradicción directa entre documentación e implementación pretendida.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The skill instructs loading credentials from a local secrets file and environment, which is privileged data access. In an agent setting, any skill that reads secrets and then performs network operations increases the chance of credential misuse, accidental disclosure, or abuse if the skill is invoked unexpectedly or modified.

Content

Scanner excerpt · SKILL.md (reported line 165)May include surrounding context.

Credenciales — nunca escribirlas en este archivo. El token y el email salen del entorno:

bash
[ -f "$HOME/.config/f100k/secrets.env" ] && set -a && . "$HOME/.config/f100k/secrets.env" && set +a
YAPPER_EMAIL="${YAPPER_EMAIL:-$(python3 -c "import json,os;print(json.load(open(os.path.expanduser('cerebro/f100k-config.json')))['email'])" 2>/dev/null)}"
[ -z "$YAPPER_TOKEN" ] && { echo "Falta YAPPER_TOKEN en ~/.config/f100k/secrets.env — no se puede guardar en Yapper"; }

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

This step couples credential presence checks with continued execution of other outbound delivery actions, creating a workflow that still moves data even when one protected integration fails. In context, the broader danger is that the skill normalizes reading secrets and dispatching content across multiple channels, which expands the blast radius of misconfiguration or unauthorized invocation.

Content

Scanner excerpt · SKILL.md (reported line 167)May include surrounding context.

bash
[ -f "$HOME/.config/f100k/secrets.env" ] && set -a && . "$HOME/.config/f100k/secrets.env" && set +a
YAPPER_EMAIL="${YAPPER_EMAIL:-$(python3 -c "import json,os;print(json.load(open(os.path.expanduser('cerebro/f100k-config.json')))['email'])" 2>/dev/null)}"
[ -z "$YAPPER_TOKEN" ] && { echo "Falta YAPPER_TOKEN en ~/.config/f100k/secrets.env — no se puede guardar en Yapper"; }

Si YAPPER_TOKEN no está, decirlo y seguir con el resto del módulo (el draft de Gmail sí se puede crear); no inventar que se guardó.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill writes generated content to local storage and transmits it to external services, but the user-facing instructions understate these data flows. Undisclosed persistence and transmission can expose sensitive or proprietary content to third-party systems without informed consent, especially in an automated daily workflow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instructions require español neutro and explicitly forbid vos/tenés, which imposes a language/locale preference in the generated output. Under SQP-3, forcing a specific language or locale without offering user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

La línea indica continuar con 'el draft de Gmail' cuando no haya token de Yapper, pero en la cabecera operativa del skill se había afirmado que no existe draft de Gmail y que la entrega es por Telegram. Esa instrucción refuerza una ruta de ejecución que contradice la modalidad de entrega documentada arriba.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

The skill explicitly posts generated script contents and associated user email to an external service (Yapper). External transmission of potentially sensitive business content is a real security/privacy risk, particularly because the skill is automated and may run regularly without per-execution confirmation.

Content

Scanner excerpt · SKILL.md (reported line 188)May include surrounding context.

text

```bash
curl -sS -L -w "\nHTTP_STATUS:%{http_code}\n" -X POST "https://yapper.formula100k.app/api/scripts" \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer $YAPPER_TOKEN" \
  --data @/tmp/yapper_guion_N.json

Static analysis

No suspicious patterns detected.