Back to skill

Security audit

benchmark-producto-formula100k

Security checks for vulnerabilities and agentic risk

Overview

The skill supports competitive research but has conflicting instructions that could lead an agent to use credentials to scrape private competitor communities and persist the results.

Review before installing. This skill is suitable only if you want a Spanish competitive-benchmark workflow using external research tools. Do not provide passwords or authorize scraping of private competitor communities unless you have clear rights and a secure handling process. Prefer limiting it to public pages, public ads, public reviews, and public profiles, and confirm where reports and raw data will be stored.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (19)

Intent-Code Divergence

High
Confidence
99% confidence
Finding
La skill declara que nunca entra con sesión ni usa credenciales para Skool, pero en otras secciones introduce scraping de comunidades privadas con credenciales. Esa contradicción puede inducir al agente o al operador a recopilar contenido no público bajo una falsa apariencia de restricción, ampliando el alcance hacia acceso autenticado a espacios privados.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
Aquí la skill expande el alcance desde benchmarking público a acceso al interior de comunidades/competidores mediante autenticación o revisión de zonas privadas. Para una tarea de inteligencia competitiva, eso cruza una línea de recolección de datos no públicos y puede facilitar exfiltración de información restringida o violación de términos de servicio.

Description-Behavior Mismatch

High
Confidence
99% confidence
Finding
The referenced capability expands the benchmark skill from public competitive intelligence into authenticated extraction of private community data. In this context, that is dangerous because it enables collection of non-public posts, member information, and internal structure from competitor communities beyond the permitted scope.

Intent-Code Divergence

High
Confidence
98% confidence
Finding
The documentation explicitly instructs use of member credentials to access Skool communities, which directly contradicts the skill’s declared no-login/public-only scope. This creates a clear pathway for unauthorized or policy-violating access to private community content under the guise of competitor research.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
Using member credentials for private-community extraction is not necessary for a normal competitor benchmark and materially increases privacy, compliance, and misuse risk. It could facilitate surveillance of private discussions, member lists, or gated materials that users did not consent to expose for competitor analysis.

Hidden Instructions

High
Category
Prompt Injection
Content
</head>
<body class="font-sans">

  <!-- HERO -->
  <header class="bg-ink text-cream-50 px-6 py-12 md:px-16 md:py-20 relative overflow-hidden">
    <div class="absolute -top-6 -right-6 washi text-3xl">BENCHMARK</div>
    <div class="max-w-5xl mx-auto">
Confidence
70% confidence
Finding
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Vague Triggers

Medium
Confidence
93% confidence
Finding
En la descripción se indica activar "SIEMPRE" ante frases como "análisis de competencia", "investigación de mercado" o "estudia el mercado de X", que pueden aparecer en conversaciones generales sin intención explícita de invocar esta skill. Aunque hay ejemplos de exclusión al final, no se delimitan condiciones negativas suficientes ni un contexto de uso estrecho para evitar colisiones.

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
La sección del navegador dice operar sin login, pero mezcla ese límite con ejemplos de funnels detrás de login y captura de áreas potencialmente privadas, creando instrucciones ambiguas. Esa ambigüedad puede hacer que un agente ejecute navegación más allá de contenido público o que intente seguir flujos autenticados no apropiados para benchmarking competitivo.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
La skill ordena guardar artefactos y espejarlos en rutas persistentes sin una confirmación clara y específica del usuario para esas escrituras. Eso puede provocar retención no deseada de datos, duplicación de información sensible sobre competidores o clientes y contaminación del espacio persistente del usuario.

Context-Inappropriate Capability

Medium
Confidence
98% confidence
Finding
La inclusión explícita de un actor de scraping para Skool que requiere credenciales introduce una capacidad de acceso autenticado innecesaria para el propósito declarado. Aunque se añada la condición de que el cliente tenga acceso, la skill normaliza el uso de credenciales para extraer interiores de terceros y aumenta el riesgo de abuso, manejo inseguro de secretos y recopilación de datos privados.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
La skill incluye un comando de shell para crear directorios y copiar archivos automáticamente, sin un paso de consentimiento específico para esa operación. En un entorno de agente, esto aumenta el riesgo de modificaciones persistentes no esperadas, sobreescritura, exposición secundaria de datos y expansión innecesaria de superficie de almacenamiento.

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
La regla "NO escribir en voseo argentino" y la instrucción de usar "español neutro: tú/tienes/puedes" fuerzan una preferencia de idioma/variante sin indicar elección o consentimiento del usuario. Esto encaja con una política de lenguaje/locale forzado sin opt-in.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The file normalizes collecting email and password input for scraping without any safeguards, handling guidance, or privacy warning. This is dangerous because it encourages unsafe credential handling practices and increases the chance of sensitive data exposure, retention, or misuse.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The file instructs the agent to use external scraping and browser services as routine fallbacks, but it does not require an explicit warning that URLs, queries, and retrieved content may be transmitted to third-party providers. This creates a transparency and privacy gap, especially in a competitive-research skill where user-supplied targets may be sensitive business intelligence.

Context-Inappropriate Capability

Medium
Confidence
87% confidence
Finding
The fallback explicitly broadens collection to LinkedIn scraping via Apify even though the skill description frames analysis around public landings, public social content, and no-login browsing. Expanding source scope during failure handling weakens user expectations and can cause collection of third-party profile data through an external scraper without clear upfront consent or necessity.

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
The guidance suggests buying access to a private Skool community to inspect non-public content, which goes beyond the skill's stated boundary of not accessing private communities. Even if framed as a suggestion to the client, it encourages bypassing the no-private-access constraint and normalizes collection from paid/private spaces for competitive intelligence.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
La regla 'No usar voseo argentino' obliga a escribir en 'español neutro' y prohíbe una variante regional concreta. Esto constituye una restricción de idioma/locale en lenguaje natural sin mecanismo de opt-in ni justificación regional explícita.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The skill explicitly forces a Spanish register ('español neutro') and forbids voseo without checking user preference. This can override the user’s requested locale or tone, causing misalignment, exclusion of certain Spanish-speaking users, and reduced trust in outputs. The surrounding content reinforces enforcement with a grep check, making the behavior intentional and systematic rather than incidental.

Natural-Language Policy Violations

Low
Confidence
89% confidence
Finding
SQP-3 applies to all file types and covers language or locale policy violations. The skill content appears to force Spanish as the only operating language, with no opt-in, alternative language option, or explanation that the skill is intended solely for a Spanish-speaking audience.

Static analysis

No suspicious patterns detected.