Back to skill

Security audit

guionizacion-historias-formula100k

Security checks for vulnerabilities and agentic risk

Overview

This is a Spanish Instagram story-script writing skill with disclosed file output and Telegram delivery, and I found no hidden code, destructive behavior, credential handling, or deceptive instructions.

Install if you want an OpenClaw skill that generates Spanish-neutral Instagram story scripts and stores them as markdown. Before using it with sensitive business material, remember that it may read profile or Segundo Cerebro context, save a draft file under guiones/historias, and deliver the full document through Telegram.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 14)May include surrounding context.

md
> - Guarda en `guiones/historias/` respetando al pie de la letra `references/output-template.md`: otra skill lo parsea.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 73)May include surrounding context.

md
> - Guarda en `guiones/historias/` respetando al pie de la letra `references/output-template.md`: otra skill lo parsea.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 210)May include surrounding context.

md
> - Guarda en `guiones/historias/` respetando al pie de la letra `references/output-template.md`: otra skill lo parsea.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

md
4. `references/ctas.md` — guía de CTAs con consecuencia

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 184)May include surrounding context.

md
4. `references/ctas.md` — guía de CTAs con consecuencia

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

El disparador 'o cualquier variación' hace que la activación de la skill sea demasiado amplia y ambigua, lo que puede provocar invocaciones no deseadas ante solicitudes parcialmente relacionadas. En un agente con acceso a lectura/escritura y envío por Telegram, esa sobre-activación puede terminar generando, guardando o compartiendo contenido sin que el usuario haya querido usar esta skill en primer lugar.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

La skill indica que guardará la salida en guiones/historias/ pero no presenta una advertencia visible ni una confirmación explícita previa sobre escritura en disco. Esto reduce la transparencia y puede causar persistencia involuntaria de contenido sensible, borradores comerciales o datos del negocio del usuario.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

La instrucción de entregar el resumen y el .md por Telegram implica transmisión de contenido a un servicio externo, pero no informa claramente al usuario ni pide consentimiento. Si el guion incorpora información del 'Segundo Cerebro', perfil o datos del negocio, existe riesgo de exfiltración accidental de contenido sensible o propietario.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

El archivo establece una política lingüística obligatoria: todo el output debe usar español neutro y reemplazar formas argentinas, incluso si aparecen naturalmente en la variante del usuario. Esto fuerza una preferencia de idioma/locale sin ofrecer opción o consentimiento, lo que encaja con una violación de política de lenguaje/locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file presents all instructions, examples, and checklist items exclusively in Spanish, and does not indicate that the skill is intended only for Spanish-speaking users or provide any user opt-in for language selection. That can violate a language/locale policy when users are not given a choice or the restriction is not justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown content appears to force a specific language for the skill material, which can violate language/locale policy when no user opt-in or alternative is provided. There is no indication that the skill is region-specific or that Spanish is an intentional, documented constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The title and instructions require the output file to follow an exact format written in Spanish, and line L003 states the skill must always save output in this exact format. This creates a language/locale constraint without any opt-in or documented region-specific justification, which matches the policy-violation criteria.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.