Back to skill

Security audit

graficos-de-video-formula100k

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed media-workflow helper that uses a third-party image generator and local output files, with some scope and environment caveats but no evidence of deception or unsafe persistence.

Install only if you are comfortable sending transcript-derived prompts to Higgsfield and saving generated PNGs locally. For OpenClaw use, provide a timed transcript as requested, confirm credit cost before generation, and treat the local ffmpeg/uvx steps as non-OpenClaw reference workflow.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger text uses an overly broad activation rule (o cualquier variación) that can cause the skill to auto-run on loosely related requests. In an agentic environment, broad invocation criteria increase the chance of the wrong skill handling user content, which can lead to unintended external generation, file creation, or processing costs without clear user intent.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Lines L013-L015 explicitly state that steps 1-3 do not run in this OpenClaw environment and that job_display and open "$DEST" do not apply. However, later sections L042-L073 and L183-L185 still document running those local commands and UI actions as if they were part of the skill flow, creating a direct contradiction in the skill's operational instructions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The phrase acompáñame la toma is ambiguous and may match benign requests that are not asking for this specific workflow. Ambiguous triggers are dangerous in automation because they can route conversations into media-processing and paid-image-generation steps the user did not clearly authorize.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
65% confidence
Finding

uvx/uv tool run commands without ==version create a rug-pull risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

La instrucción establece de forma obligatoria un único registro lingüístico para todo contenido generado, sin ofrecer elección al usuario ni documentar una justificación de cumplimiento regional. Esto constituye una restricción de idioma/locale impuesta por defecto.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs downloading externally hosted image URLs with curl and saving outputs locally, but it does not visibly warn the user that data will be exchanged with a third-party service and retrieved from external URLs. In this context the danger is unauthorized or unclear third-party data flow: user-derived content is sent to Higgsfield and externally hosted results are fetched, which can create privacy, compliance, and consent issues.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The manifest description frames the skill as starting from a provided transcript with timestamps and generating scrapbook graphics, emphasizing that it does not edit the video. Yet the main pipeline in L042-L073 includes validating a video file, extracting audio with ffmpeg, and transcribing it with mlx-whisper, which materially broadens the behavior beyond operating on an already-supplied transcription.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.