Back to skill

Security audit

broll-vsl-formula100k

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its stated video-generation purpose, but it deserves review because it can inspect and upload personal reference photos and persist photo-linked media IDs for future reuse without enough per-use control.

Install only if users understand that personal reference photos may be uploaded to Higgsfield and their media IDs may be reused later. Prefer providing one specific approved photo, confirm costs before generation, avoid giving access to broad selfie folders, and ask the agent not to save or publish media IDs unless reuse is explicitly desired.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The activation trigger includes "any variation" combined with broad long-script/video phrasing, which can cause the skill to fire on loosely related requests. Over-broad invocation increases the risk of unintended tool use, unnecessary media processing, and access to user content when a more limited or different skill should have handled the request.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The 'Cuándo activar' section uses generic phrases like requests for visual resources and cinematic clips, which may overlap with ordinary editing, ideation, or asset-planning tasks. In context, that can lead the agent to invoke costly external generation workflows or request extra user assets without sufficiently clear user intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Las instrucciones de preguntas al usuario están definidas únicamente en español y no ofrecen alternativa de idioma. Según la política, forzar un idioma o locale sin elección explícita del usuario constituye una violación de política lingüística.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill instructs the agent to inspect a local folder of personal selfies and select among multiple private photos, which expands data access beyond what is strictly necessary to fulfill a B-roll request. Even if the goal is legitimate avatar generation, broad access to personal image repositories increases the chance of over-collection and unintended exposure of sensitive biometric or personal images.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly directs the agent to store and reuse a user's reference-photo media identifier across future sessions, creating persistent linkage to biometric-like personal media. Cross-session retention without clear consent, retention limits, or revocation controls increases privacy risk and the chance of unauthorized reuse.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Including the exact reference-photo media ID in the final deliverable unnecessarily exposes an identifier tied to the user's uploaded reference image. That identifier could be reused, shared, or logged in downstream systems, increasing the risk of unintended access or correlation of personal media across projects.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The instruction actively claims the agent can 'leer 3-4 archivos con Read y elegir' the best photo based on visual characteristics like face angle and lighting. That contradicts the actual capability implied by the tool name and typical behavior, because evaluating image composition is not something plain file reading accomplishes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
70% confidence
Finding

La instrucción prescribe una caracterización demográfica específica en lenguaje natural para todos los clips con avatar. Aunque puede reflejar un caso de uso concreto, aquí aparece como mandato general de la skill sin justificación contextual ni opción de ajuste, lo que puede entrar en conflicto con políticas organizacionales sobre atributos sensibles en instrucciones predefinidas.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.