Back to skill

Security audit

crea-tu-app-f100k

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its app-building purpose, but it needs review because it can deploy to a user's Vercel account and handle credentials while giving conflicting approval guidance.

Install only if you are comfortable with an agent guiding deployment to your own Vercel account, using your service keys, and sending progress over Telegram. Before use, require explicit approval immediately before any production deploy, avoid sending secrets through chat, rotate any key shared during testing, and add privacy safeguards for apps that process faces, photos, chats, documents, audio, or sensitive personal content.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The OpenClaw-specific section says deployment can proceed without asking for the user's final approval, which directly conflicts with the later workflow requirement to stop at human checkpoints and only publish with explicit consent. In a skill that can deploy to a user's Vercel account, contradictory instructions increase the chance the agent will take an irreversible external action without informed confirmation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad enough to match ordinary requests about creating an app, which can cause the skill to activate in contexts where the user did not intend a high-touch workflow involving Telegram, external browsing, credential setup, and deployment. Overbroad activation is especially risky here because the skill later handles sensitive operations across third-party accounts.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill states certain helper skills do not exist in this environment, but later instructions still direct the agent to use them. This inconsistency can cause fallback behavior that is undefined, leading the agent to skip safeguards or improvise sensitive design/debugging decisions during account setup, key handling, or deployment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description and body describe browsing the user's public assets, sending progress over Telegram, instructing the user to add secrets in Vercel, and potentially storing a key in .env.local for testing, but they do not present a clear upfront warning that sensitive credentials and external account actions are part of the workflow. Users may begin the process without understanding the privacy, security, and account-control implications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

These entries describe apps that analyze user photos and generate or transform human images, including headshots and avatars, without warning about biometric-like data, identity misuse, consent, or image retention. Because this catalog feeds a no-code app-building wizard for students, the omission increases the chance that privacy-sensitive image features are built and deployed without safeguards.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

These catalog entries promote apps that process sensitive personal content such as audio, meetings, PDFs, and emotionally revealing text without any accompanying privacy, consent, retention, or confidentiality guidance. In this skill context, the document is used to recommend and scaffold real app builds for end users, so omissions here can propagate directly into deployed products that mishandle personal or confidential data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The catalog includes chat-screenshot and document-analysis app ideas that can expose confidential conversations, legal/work documents, or other sensitive records, yet it provides no warning about redaction, authorization, or secure handling. In this skill, the content is operational guidance for building customer-facing apps, so the lack of guardrails materially raises the risk of accidental disclosure or unauthorized processing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly instructs collecting branding cues from a user's Instagram or website, including requesting Telegram screenshots of Instagram content, but it does not include any privacy notice, consent boundary, or data-minimization guidance. Even if intended for benign brand customization, this can lead to unnecessary collection and processing of personal or business profile data beyond what is strictly needed.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The section "Cómo hablarle a la alumna (tono — no opcional)" forces a fixed language/tone policy for all interactions. This is a natural-language policy concern because it removes user choice over communication style and framing rather than offering adaptation based on the user's preference.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.