Back to skill

Security audit

calendarizador-contenido-formula100k

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Spanish content-calendar generator, but it needs review because it can use paid external research/transcription services and tells the agent to install an unpinned package for Excel output.

Review before installing if you do not want automatic third-party research, paid Apify/Supadata-style calls, or environment package installation. Use it with an explicit rule to ask before network research or `pip install`, preinstall or pin `openpyxl` if XLSX is needed, and avoid providing private client/profile details unless you are comfortable sending that context to the configured research tools.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The code is narrower than the declared description. It only accepts JSON containing prebuilt rows and outputs formatted calendar files. There is no orchestration of other skills, no transcription, no script/carrusel generation from loose ideas, and no weekly allocation logic according to the stated methodology percentages. The primary purpose is still related—calendar file generation for reels/carruseles—but the declared description materially overstates the behavior and workflow automation actually present in this code chunk.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 15)May include surrounding context.

md
> - El script `references/generate_calendar.py` corre con python3 sin librerías extra: úsalo con `--output-dir guiones/calendarios/`. El XLSX solo si `openpyxl`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 265)May include surrounding context.

md
> - El script `references/generate_calendar.py` corre con python3 sin librerías extra: úsalo con `--output-dir guiones/calendarios/`. El XLSX solo si `openpyxl`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 376)May include surrounding context.

md
> - El script `references/generate_calendar.py` corre con python3 sin librerías extra: úsalo con `--output-dir guiones/calendarios/`. El XLSX solo si `openpyxl`

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs the agent to run pip install openpyxl --quiet at runtime, which introduces unpinned third-party code into the execution environment. This creates a supply-chain and environment-integrity risk: a compromised package, dependency confusion, or unexpected transitive behavior could lead to arbitrary code execution or persistent modification of the agent host.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 377)May include surrounding context.

md
- `references/ejemplos-cta.md` — Bank de CTAs por tipo de slot

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill describes file read/write behavior and execution of a local script, but does not declare an explicit tool scope or permissions boundary. In an agent environment, missing scope declarations can cause the skill to inherit broader-than-necessary capabilities, increasing the chance of unintended file access or modification.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest frames the skill primarily as assembling weekly calendars from provided scripts, ideas, or links. The documentation expands this into fetching viral references via Apify, web search, Supadata, and vidIQ-related tooling, which is broader than merely organizing user-provided content into CSV/XLSX calendars.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest at L003 says the skill supports three modes: ready scripts, loose ideas developed via other skills, and video links transcribed and rewritten. The code documentation introduces a fourth default mode based only on niche/avatar briefs, requiring viral-reference hunting and external analysis, which is a materially broader behavior than the manifest claims.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The instruction says 'Default = español neutro tú,' which imposes a default language/locale behavior unless the client writes in voseo. This is a natural-language policy concern because it forces a specific linguistic variant without explicitly offering the user a choice or opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

Todo el contenido e instrucciones del skill están redactados exclusivamente en español y no indican que el uso esté limitado a usuarios hispanohablantes ni que exista una elección de idioma. Según la política, forzar un idioma sin opt-in o justificación clara puede constituir una violación de política lingüística.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file presents all instructions and CTA examples only in Spanish, and there is no indication that the user can opt into another language or that the locale restriction is required. Under the policy, forcing a specific language without user choice is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.