Back to skill

Security audit

guionizacion-formula100k

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Spanish video-script writing skill, with disclosed but privacy-relevant behavior around web/social lookups and saving generated scripts.

Install only if you are comfortable with the agent using web or connected social-data tools to research viral references and saving generated scripts locally. Avoid putting sensitive personal stories, confidential business strategy, or private handles into prompts unless you want them included in saved drafts or external search terms.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

La descripción activa la skill para un abanico muy amplio de solicitudes relacionadas con guiones, estructuras, hooks y planificación de video, con lenguaje como 'usar SIEMPRE'. Eso puede forzar la selección de esta skill en contextos donde no es la mejor opción, aumentando el riesgo de sobrealcance, uso inapropiado de herramientas externas y aplicación de instrucciones complejas o persistentes sin necesidad.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 136)May include surrounding context.

md
Ver instrucciones completas en: `references/verificacion-viralidad.md`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 239)May include surrounding context.

md
Ver instrucciones completas en: `references/verificacion-viralidad.md`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 698)May include surrounding context.

md
Ver instrucciones completas en: `references/verificacion-viralidad.md`

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

La instrucción de guardar cada guion en guiones/ impone persistencia local de contenido potencialmente sensible sin avisar ni pedir consentimiento al usuario. Los guiones pueden incluir historias personales, datos del negocio, handles de redes o información estratégica, por lo que almacenar automáticamente esos datos incrementa exposición, retención no deseada y riesgo de acceso posterior.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

En L0075-L0076 el ejemplo usa una cifra concreta sobre una clienta, y en L0100-L0102 el análisis la presenta como credibilidad basada en números específicos. Sin embargo, el mismo documento dice en L0022-L0024 que las cifras de ejemplos EN BOCA son ilustrativas y en L0750 critica 'estudios muestran' sin fuente, así que la documentación aquí trata como real una data que el propio archivo no permite asumir como real.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

En L0552-L0565 el ejemplo de la Estructura 8 no contiene la frase 'si no te haces viral, no sirves', pero el análisis en L0569-L0577 se apoya en esa cita y además habla de 'datos reales'. Eso contradice el contenido inmediato del ejemplo y documenta un funcionamiento retórico distinto al realmente mostrado.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

En L0750 el documento dice que 'estudios muestran' sin fuente viola la regla de no inventar data; sin embargo, en L0766-L0769 el análisis vuelve a elogiar la afirmación como 'estadísticas de engagement emocional'. Esto es una contradicción directa entre la documentación correctiva y la explicación posterior de la misma estructura.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The module is configured to run for essentially any new script-writing request, which can trigger unnecessary external searching and data-gathering even when the user did not ask for viral-reference lookup. Overly broad activation increases the chance of unneeded tool use, privacy leakage through third-party queries, and scope creep from content writing into unsolicited web/MCP access.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This file is primarily written in Spanish, but the example at L2627-L2628 switches to English ('If you want to sell to the poor...'). That introduces a language change without indicating user choice or a justified locale constraint, which can conflict with language/locale consistency expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The instruction to switch searches into English without explicit user opt-in can cause the agent to expand the search scope beyond the user's requested language or context. While not severe on its own, it can produce less relevant results, alter user intent, and trigger avoidable external queries across broader datasets.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.