Back to skill

Security audit

calendario-actividades-skool-f100k

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Spanish-language calendar planning and rendering helper with normal local file, npm, and Chrome-rendering behavior for its purpose, though users should review dependency and trusted-input risks.

Install only if you are comfortable with a skill that installs npm dependencies, stores per-community calendar configs locally, and renders generated HTML through a local Chrome/Chromium binary. Use trusted calendar config text and logos, review the generated PNG/HTML before sending it, and update or pin the Puppeteer dependency tree if this will run in a production or multi-user environment.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (15)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

La parte de renderizado sí coincide claramente con la descripción: toma configuración, tema de marca y produce HTML + PNG usando Chrome. Sin embargo, la descripción presenta una capacidad más amplia y principal: construir el calendario mensual de actividades de comunidad/Skool desde una rutina recurrente y eventos, incluyendo dos caminos específicos (desde cero con metodología F100K o clonar mes anterior). En el código proporcionado no aparece ninguna lógica para generar el calendario desde cero, clonar un mes previo, ni ajustar automáticamente sesiones/eventos entre meses; sólo consume un archivo JSON existente y lo renderiza. Por tanto, hay una discrepancia material entre la skill declarada como planificador/calculador integral y el comportamiento real observado, que es un renderer/exportador.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 13)May include surrounding context.

md
> - Arranca desde `plantillas/dinamicas-genericas.json` (o `blanco.json`). La config real de FÓRMULA 100K no viaja en este paquete. La config de su comunidad gu

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

md
> - Arranca desde `plantillas/dinamicas-genericas.json` (o `blanco.json`). La config real de FÓRMULA 100K no viaja en este paquete. La config de su comunidad gu

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 76)May include surrounding context.

md
> - Arranca desde `plantillas/dinamicas-genericas.json` (o `blanco.json`). La config real de FÓRMULA 100K no viaja en este paquete. La config de su comunidad gu

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 84)May include surrounding context.

md
> - Arranca desde `plantillas/dinamicas-genericas.json` (o `blanco.json`). La config real de FÓRMULA 100K no viaja en este paquete. La config de su comunidad gu

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 13)May include surrounding context.

md
> - Arranca desde `plantillas/dinamicas-genericas.json` (o `blanco.json`). La config real de FÓRMULA 100K no viaja en este paquete. La config de su comunidad gu

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 76)May include surrounding context.

md
> - Arranca desde `plantillas/dinamicas-genericas.json` (o `blanco.json`). La config real de FÓRMULA 100K no viaja en este paquete. La config de su comunidad gu

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 111)May include surrounding context.

md
Cada tema vive en `themes/<nombre>/` con `theme.json` (CSS vars + tipografía) y un `fondo.jpg` opcional:

Known Vulnerable Dependency: extract-zip==2.0.1 — 2 advisory(ies): CVE-2026-19693 (extract-zip allows arbitrary file writes through symlink archive entries); CVE-2026-56876 (extract-zip unvalidated symlink path traversal)

High
Category
Supply Chain
Confidence
88% confidence
Finding

extract-zip 2.0.1 is a real supply-chain risk because the listed advisories describe arbitrary file write and symlink path traversal during archive extraction. In this lockfile it is only a transitive dependency of Puppeteer's browser-management stack, so exploitability depends on the skill ever extracting attacker-controlled ZIP content; the package presence alone does not prove active exploitation, but the dependency is genuinely vulnerable.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ip-address==10.2.0 — 3 advisory(ies): CVE-2026-54272 (ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSR); CVE-2026-69198 (ip-address: a CIDR suffix on the parsed address suppresses special-use classific); CVE-2026-69192 (ip-address: Address4 decodes leading-zero octets as decimal while resolvers deco)

High
Category
Supply Chain
Confidence
80% confidence
Finding

ip-address 10.2.0 has real advisories involving misclassification of special-use and mapped addresses, which can undermine SSRF or network allow/deny-list protections when the library is used for security decisions. Here it is a deep transitive dependency under proxy-agent/socks, and this skill's stated purpose is HTML-to-Chrome-to-PNG rendering rather than access-control enforcement, so the context makes practical impact lower unless the code relies on proxy or address classification for outbound request restrictions.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

El manifiesto enumera ejemplos concretos, pero luego amplía la activación a "cualquier variación" que combine conceptos muy comunes dentro del dominio de comunidad/Skool y calendario mensual. Esa redacción deja borrosos los límites exactos de activación y puede causar invocaciones no deseadas frente a solicitudes parecidas pero no equivalentes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document declares lang="es", and the visible UI strings throughout the template are hard-coded in Spanish. This imposes a specific language/locale on users without any opt-in, alternative selection, or documented region-specific justification, which matches the natural-language locale policy violation criteria.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This manifest file only provides a broad capability description in natural language and does not define any explicit trigger phrases, scope limits, or exclusion conditions. In manifest files, such vague invocation descriptions can contribute to unintended activation because there is no indication of when the skill should or should not be used.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
92% confidence
Finding

Using a caret range for puppeteer-core allows newer minor/patch releases to be installed automatically, which can introduce supply-chain risk, unexpected behavior changes, or breakage in a rendering pipeline that launches a browser. In an agent skill that renders user-influenced HTML via Chrome, dependency drift is more sensitive because browser automation libraries have a large attack surface and frequently interact with untrusted content.

Content

Scanner excerpt · package.json (reported line 11)May include surrounding context.

json
"render": "node render.js"
  },
  "dependencies": {
    "puppeteer-core": "^24.42.0"
  }
}

Static analysis

No suspicious patterns detected.