Back to skill

Security audit

generador-ganchos-formula100k

Security checks for vulnerabilities and agentic risk

Overview

This is a transparent Spanish-language workflow for generating and testing short-video hooks; its AI media generation, predictor use, and local report saving are disclosed and fit the purpose.

Install only if you are comfortable sending prompts, generated media, and possibly user-provided reference images to Higgsfield or Apify when those integrations are used. Confirm credit costs before generation, avoid using a person's face or private material without consent, and adjust the Spanish dialect requirement if your audience expects a different voice.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 17)May include surrounding context.

md
> - La referencia a los criterios de `evaluador-ganchos-formula100k` apunta a una skill que no viene en este paquete: usa `criterios.md` de esta misma skill.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 84)May include surrounding context.

md
> - La referencia a los criterios de `evaluador-ganchos-formula100k` apunta a una skill que no viene en este paquete: usa `criterios.md` de esta misma skill.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 128)May include surrounding context.

md
> - La referencia a los criterios de `evaluador-ganchos-formula100k` apunta a una skill que no viene en este paquete: usa `criterios.md` de esta misma skill.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 86)May include surrounding context.

md
- `output-template.md` — formato del reporte LAB con ranking y brief de ganadora

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 214)May include surrounding context.

md
- `output-template.md` — formato del reporte LAB con ranking y brief de ganadora

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger scope is overly broad because it activates on essentially any request that involves designing or proposing hooks. That can cause the agent to invoke this skill in contexts where the user did not explicitly want AI media generation, external plugin use, or this workflow, increasing the chance of unintended actions, unnecessary cost, or mishandling of user input.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Mandating a specific dialect ('Español neutro obligatorio') without user choice reduces user control and can override explicit preferences or accessibility needs. While not a classic security flaw, it is a policy/behavioral overreach that can cause the agent to ignore user instructions and degrade trust, especially for locale-sensitive or identity-sensitive communication.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file provides all operational instructions exclusively in Spanish and does not mention that the skill is Spanish-only or offer an opt-in language choice. Under the policy, forcing a specific language without user choice is a natural-language locale violation unless the restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Lines L011-L013 state that no family shows a defensible performance difference and that no molde outperforms another. However, L152-L153 says '¿Sabías que...?' is 'el de peor mediana del análisis,' which is a direct documentation-level contradiction about comparative performance claims.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instruction explicitly requires 'Español neutro' and says to never use voseo forms like 'vos' or 'tenés'. This imposes a language/locale style constraint without offering the user a choice or documenting a justified regional limitation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

Reinforcing the no-voseo rule in anti-error guidance makes the behavior more rigid and increases the likelihood that the agent will disregard explicit user preference. In context this is less dangerous than code execution or data exfiltration, but it still creates an instruction-priority conflict that can lead to incorrect or unwanted output.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.