Back to skill

Security audit

caso-estudio-contenido-f100k

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for creating a content case-study deliverable, but it also directs live Vercel deployment with a user token and Telegram delivery without enough scoping or final deployment control.

Review before installing if you do not want an agent to use Apify, Composio, Telegram, or Vercel. If you install it, use a narrowly scoped Vercel token, require the agent to name the target project/domain before running any deploy command, and keep CSV or page delivery inside a recipient you have verified.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The description presents a comprehensive end-to-end skill that should analyze a student's niche and produce the complete case-study deliverable set. In contrast, this code chunk is a narrow renderer. It accepts already-structured data.json and outputs index.html with inline CSS. All substantive content—viral references, patterns, scripts, hooks, calendar entries, and month-2 plan—must already exist in the input. There is no logic for niche research, generation, orchestration of multiple stages, CSV creation, checkpoint handling, or trigger activation. While rendering the final HTML case study is consistent with one part of the declared purpose, the code does not implement the skill's primary claimed behavior, so this is a material description-behavior mismatch.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill instructs file reads/writes and artifact generation but declares no explicit tool scope or permissions boundary. In an agent environment, missing least-privilege constraints can let the skill access or modify files beyond what is necessary, especially when combined with dynamic paths and orchestration steps.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill's declared purpose is content artifact generation, but it also performs production deployment using a user-supplied Vercel token. That expands the trust boundary from local content generation into external infrastructure modification, which can result in unintended publication, overwriting projects, or misuse of deployment credentials.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Including credential-based production deployment is broader than necessary for generating a case-study page and calendar. Excess capability increases the blast radius if the skill is misused, the token is mishandled, or prompt injection causes unintended actions against the user's Vercel environment.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs using the user's Vercel token for deployment and then sending the resulting URL and CSV over Telegram. This combines credential-backed external actions with data transmission over another channel, increasing the risk of accidental data leakage, unauthorized publication, and misuse if Telegram routing or operator identity is not strictly verified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill states that outputs must target a Spanish-speaking audience in 'español neutro — NO voseo', which imposes a locale/language variant requirement as a non-optional rule. This is a natural-language policy concern because it does not offer the user a choice or indicate opt-in for that dialect preference.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

At L175, the skill states 'No automatiza el deploy a Netlify', which frames deployment automation as outside scope. However L019 explicitly instructs deploying the page directly to Vercel using VERCEL_TOKEN and sending the URL, meaning the skill does perform automated deployment to a hosting provider. This is an active contradiction in the skill's own documentation about whether deployment automation is part of its behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The template sets lang="es", and the script's user-facing content is entirely in Spanish. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is clearly documented and justified; this file does not provide such opt-in or justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.