Back to skill

Security audit

carrusel-render-formula100k

Security checks for vulnerabilities and agentic risk

Overview

This skill is a purpose-aligned carousel-to-PNG renderer, but users should be aware that it may read selected personal photos, install npm dependencies, and make font/network requests during rendering.

Install only if you are comfortable with a Spanish, Formula 100K-specific renderer that can run npm/Node/Chromium, write carousel outputs, read selected photos, and contact external font hosts unless rendering is constrained. Prefer using explicit photo paths, keeping outputs in the intended entregables/carruseles folder, running dependency audits/updates, and disabling or allowlisting network requests during Chromium export.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (25)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

La parte de exportación a PNG con Chromium headless sí coincide parcialmente con la descripción. Sin embargo, la descripción presenta una capacidad mucho más amplia: diseñar/renderizar el carrusel completo a partir de un guion, escribir el HTML, aplicar estilos definidos y usar fotos de la usuaria. El código suministrado no hace nada de eso; únicamente abre un HTML local existente y captura screenshots de elementos .slide. Por tanto, hay una discrepancia material entre la finalidad declarada y el comportamiento real, aunque no se observan capacidades peligrosas extra no declaradas más allá del acceso esperado al sistema de archivos local y al navegador para exportar imágenes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

La discrepancia es material. La descripción presenta una herramienta general para convertir guiones de carrusel en PNG listos para Instagram, con estilos configurables y soporte para fotos de la usuaria. Sin embargo, el código mostrado es un generador estático: define CSS, texto, iconos, lista de apps y capturas concretas, y escribe archivos 'slide-01.html' a 'slide-08.html'. No hay parsing de guion, parámetros de entrada, selección de estilo, composición basada en instrucciones del usuario ni exportación de imagen. El acceso a recursos locales (_orig25.jpg y varias capturas PNG) sí está relacionado con diseño de slides, pero el comportamiento principal no coincide con lo declarado.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 167)May include surrounding context.

md
- `export.js` — script de Puppeteer que exporta PNGs

Known Vulnerable Dependency: extract-zip==2.0.1 — 2 advisory(ies): CVE-2026-19693 (extract-zip allows arbitrary file writes through symlink archive entries); CVE-2026-56876 (extract-zip unvalidated symlink path traversal)

High
Category
Supply Chain
Confidence
90% confidence
Finding

The lockfile includes extract-zip 2.0.1 as a transitive dependency of @puppeteer/browsers. The cited symlink/path traversal issues can enable arbitrary file writes when extracting a malicious archive; in this skill, the main risk is during browser/package download or archive handling in the dependency chain rather than direct user-controlled ZIP extraction, so the issue is real but context-limited.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ip-address==10.2.0 — 3 advisory(ies): CVE-2026-54272 (ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSR); CVE-2026-69198 (ip-address: a CIDR suffix on the parsed address suppresses special-use classific); CVE-2026-69192 (ip-address: Address4 decodes leading-zero octets as decimal while resolvers deco)

High
Category
Supply Chain
Confidence
84% confidence
Finding

The lockfile includes ip-address 10.2.0 via the proxy-agent/socks stack, and the listed advisories concern incorrect IP parsing and special-use address classification. Those flaws are security-relevant when code relies on the library to enforce SSRF or network access restrictions; given this skill renders user-influenced HTML in headless Chromium, any network-fetch controls around proxies or address validation would make this dependency more sensitive.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ws==8.20.0 — 2 advisory(ies): CVE-2026-45736 (ws: Uninitialized memory disclosure); CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
88% confidence
Finding

The lockfile includes ws 8.20.0 through puppeteer-core, and the noted advisories describe memory disclosure and memory-exhaustion denial of service in WebSocket handling. In this skill, Puppeteer communicates with Chromium over WebSocket/DevTools channels, so a vulnerable ws version could contribute to information leakage or service instability if an attacker can influence or abuse those connections.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest says the skill should render a supplied carousel script into finished PNG-ready slides, integrating the user's requested content and style. In this file, the cover, app slides, CTA, and all text/content are hard-coded around a specific six-app theme, with no parsing or consumption of an external script, so the implemented behavior is substantially narrower and different from the claimed renderer purpose.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/ejemplo-completo.html (reported line 686)May include surrounding context.

html
</head>
<body>

<!-- ============ SLIDE 1 — PORTADA ============ -->
<div class="slide s1">
  <div class="tape tape-1"></div>
  <div class="tape tape-2"></div>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/ejemplo-completo.html (reported line 795)May include surrounding context.

html
</div>


<!-- ============ SLIDE 4 — Higgsfield ============ -->
<div class="slide s4">
  <div class="tape tape-1"></div>
  <div class="tape tape-2"></div>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/fotos-reales.md (reported line 36)May include surrounding context.

~ creadora indie ~
```

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding

La skill instruye al agente a usar capacidades de entorno y ejecución local (npm install, resolver CHROME_PATH, invocar Node/Chromium) pero no declara un alcance explícito de herramientas o permisos. Esto es peligroso porque amplía implícitamente la superficie operativa: un agente podría ejecutar comandos o depender de variables/rutas del sistema sin una política visible ni mínima de privilegios.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Los triggers de activación son demasiado amplios y pueden hacer que la skill se dispare ante peticiones comunes de diseño no destinadas a esta automatización. En un contexto donde la skill puede leer archivos, copiar fotos y ejecutar renderizado local, una activación espuria puede provocar acciones no deseadas, uso indebido de recursos o tratamiento accidental de contenido sensible.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Activar la skill por la mera presencia de patrones como Slide 1 / Slide 2 es ambiguo y puede capturar cualquier texto con estructura similar, incluso cuando el usuario no pidió renderizado. Dado que la skill además sugiere acceder a archivos locales y ejecutar herramientas del sistema, esta ambigüedad aumenta el riesgo de acciones automatizadas sobre entradas no confirmadas.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The document enforces Spanish-language instructions and user-facing phrasing throughout, such as the CTA examples and style directives, without indicating that another language may be used. Under the policy, forcing a specific language without user choice is a natural-language policy concern unless clearly justified.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The exporter opens attacker-influenced local HTML in a real browser and waits for network activity to settle, which allows implicit outbound requests from resources embedded in the HTML such as remote images, fonts, CSS, or tracking URLs. In this skill's context, the HTML is generated from user-provided carousel content and user photos, so this can leak metadata or trigger server-side requests from the host environment, creating SSRF/privacy exposure during rendering.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest emphasizes integrating the user's real photos in multiple presentation formats. Here, the background photo is always loaded from a fixed local file (_orig25.jpg), and screenshots are loaded from fixed local asset names, indicating template-specific assets rather than user-supplied photos being incorporated dynamically.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The string literal explicitly says "Le hablo en español" and the file’s user-facing slide copy is entirely in Spanish, which indicates a fixed language/locale assumption. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is documented and justified.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest explicitly describes writing HTML and exporting to PNG with server-side headless Chromium. This file only wraps slide HTML and writes slide-XX.html files to disk, with no PNG rendering or browser-export step present in the actual operations shown here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly instructs the agent to read personal photos to inspect their contents and copy them into an output folder, but it does not require confirming user consent, scoping access to user-approved files, or minimizing retention. In a skill that handles real user images, this creates a real privacy risk because the agent may inspect and duplicate sensitive personal data beyond what the user expected.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The workflow tells the agent to list a photo directory, rank images by metadata such as modification date or size, and then inspect several candidates. Even without exfiltration instructions, this is still privacy-sensitive processing of personal image collections and filesystem metadata without transparency, consent boundaries, or data-minimization controls.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The scrapbook style explicitly loads Google Fonts from an external CDN, which causes an outbound network request during rendering and can leak metadata such as IP address, timing, and usage patterns to a third party. In this skill's context, the renderer uses headless Chromium on a server, so the request would originate from infrastructure rather than the end user, but it still creates unnecessary external dependency, privacy exposure, and non-deterministic rendering.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file's comments, usage text, and runtime messages are written in Spanish, which imposes a specific language on users. The policy allows locale constraints only when they are justified or when the user is offered a choice, neither of which appears here.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
92% confidence
Finding

The dependency uses a caret range, which allows newer minor/patch versions of puppeteer-core to be installed over time. That can lead to non-reproducible builds and accidental adoption of a compromised or breaking upstream release, which matters here because this skill drives headless Chromium to render user-controlled content.

Content

Scanner excerpt · package.json (reported line 11)May include surrounding context.

json
"export": "node export.js"
  },
  "dependencies": {
    "puppeteer-core": "^24.42.0"
  }
}

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document explicitly sets lang="es", and all visible user-facing content is written only in Spanish. For an HTML file, this is a natural-language locale constraint without any indication of user opt-in or a documented region-specific reason, which matches the policy concern for forced language/locale.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The template imports Google Fonts from external domains, which introduces outbound network access and a third-party dependency into what is otherwise a local HTML rendering asset. In a headless Chromium rendering pipeline, this can leak request metadata and create nondeterministic rendering or tracking risk if the environment is expected to be offline or self-contained.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.