Back to skill

Security audit

historias-a-imagenes-nanobanana

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Instagram Story image-generation workflow that uses user-provided photos and image services, with privacy considerations but no artifact-backed malicious behavior.

Install only if you are comfortable giving the agent access to a curated folder of personal brand photos and sending selected images to Gemini or Higgsfield for generation. Use a dedicated photo folder, avoid including unrelated private images, review the estimated cost confirmation before generation, and periodically delete old files in `entregables/historias/` and the preset at `cerebro/preset-historias.json` if you no longer want them retained.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (15)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill description uses very broad activation language such as 'cualquier variación' combined with a common user intent, which can cause the agent to invoke this skill in situations the user did not clearly authorize. In a system that can access files, photos, presets, Telegram, and external generation engines, overbroad triggering increases the chance of unintended data access, storage, cost-incurring actions, and side effects.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

md
1. `references/parser-guion.md` — cómo parsear el .md del guion

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 80)May include surrounding context.

md
1. `references/parser-guion.md` — cómo parsear el .md del guion

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

md
3. `references/prompt-builder.md` — fórmula del prompt para generar el slide

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 129)May include surrounding context.

md
3. `references/prompt-builder.md` — fórmula del prompt para generar el slide

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 159)May include surrounding context.

md
3. `references/prompt-builder.md` — fórmula del prompt para generar el slide

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill instructs persistent storage of user photos, output images, and presets/metadata without a clear privacy notice, retention policy, or explicit consent flow. Because the content involves personal brand photos and Telegram delivery, this creates a meaningful privacy risk if users are unaware that sensitive images and run metadata will be retained across sessions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Las instrucciones establecen "ESPAÑOL NEUTRO OBLIGATORIO" y ordenan corregir automáticamente argentinismos, lo que fuerza una variante lingüística concreta. Esto constituye una restricción de idioma/locale sin opción para que el usuario conserve su registro original ni justificación de cumplimiento regional.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The design explicitly returns and displays absolute local photo paths, which can reveal sensitive information such as usernames, home directory structure, project names, and storage layout. Even if only shown to the user, exposing full paths unnecessarily broadens privacy leakage and increases the chance those details are copied into logs, prompts, or downstream systems.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill instructs shell-based conversion of user-supplied HEIC files using ImageMagick, which introduces external tool execution and file creation beyond the core rendering logic. This is risky because unsafe invocation patterns, malformed files, or uncontrolled paths can expose the host to command execution, parser bugs, or unintended file writes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The conversion guidance tells the skill to create a new JPG from a user photo but provides no warning, consent flow, or handling constraints for derived files. This is dangerous because it can silently duplicate sensitive personal images, leave residual files in uncontrolled locations, and modify the user's data environment in ways they did not expect.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file is written entirely in Spanish and presents requirements as mandatory, indicating the skill should operate in that language by default. Under the policy, forcing a specific language without offering user choice or documenting a justified locale constraint is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This file presents all operational guidance, prompts, and user-facing instructions in Spanish, including confirmation text and warnings. Under the language/locale policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This markdown file contains user-facing instructions and examples exclusively in Spanish, including mandated CTA text such as "Responde [PALABRA_CLAVE] y te [acción]". Under the stated policy, forcing a specific language without an explicit user choice is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The manifest describes converting a story script into final Instagram Story images and selecting the best base photo automatically. This document expands that into inspecting file creation dates, subfolder organization, and optionally using ImageMagick-based visual hashing, which are broader local-analysis capabilities not explicitly stated in the skill purpose.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.