Back to skill

Security audit

infografia-reel-formula100k

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed workflow for creating infographic reels, with expected use of generation, research, download, and local output files.

Install only if you are comfortable with the skill using third-party generation and research services, consuming media-generation credits after confirmation, and saving generated files plus a reusable brief in the workspace. Review the Gemini/Higgsfield wording if you need strict control over which provider creates the base image.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (18)

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

El disparador 'activar SIEMPRE' con una condición abierta ('o cualquier variación...') amplía excesivamente el alcance de la skill y favorece activaciones no intencionales. Eso puede secuestrar consultas parcialmente relacionadas, provocar uso indebido de herramientas externas, consumo de créditos y procesamiento de URLs/contenido no deseado sin una validación suficientemente acotada.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description says to use the Higgsfield MCP as the 'motor único' for creating the reel, but the file later states the base image may come from Gemini and that article/YouTube/topic ingestion should use WebFetch, Supadata, and Tavily. Those are substantive behaviors, not incidental implementation details, so the documented behavior exceeds the manifest's stated single-engine scope.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Lines L014-L016 say the base image can be generated by Gemini when a Gemini API key is available, with Higgsfield used only as fallback for the image and required for video. Later, L023-L024 and L051-L053 describe Higgsfield as the unique engine for both image and video generation. This is an active contradiction in the skill's own instructions about what engine actually performs image generation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

La instrucción de detectar automáticamente el tipo de input y proceder sin preguntar reduce fricción, pero también elimina una barrera de seguridad importante frente a entradas ambiguas o malformadas. En contexto de URLs y herramientas externas, esto puede llevar al agente a investigar, extraer o procesar recursos equivocados, aumentando riesgo de acciones no deseadas y gasto innecesario.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

La regla exige que todo copy en español sea "español NEUTRO, no argentino" y ordena reemplazos obligatorios de voseo por tuteo. Esto fuerza una variante lingüística concreta sin ofrecer elección al usuario ni justificar una restricción regional o de cumplimiento.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations. This markdown file presents all instructions and examples exclusively in Spanish, and nowhere offers user opt-in for language selection or explains that the skill is intended only for a Spanish-speaking or region-specific context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill hard-codes a linguistic normalization rule that rewrites Argentine Spanish into neutral Spanish without the user's consent. This can override user intent, reduce fidelity to the requested voice or audience, and create problematic personalization behavior by silently transforming dialect-specific content.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill expands from deterministic infographic generation into open-ended web research for vague user prompts, which increases the chance of pulling in untrusted external content and following links or summaries beyond the user’s original supplied material. In a skill that can ingest arbitrary topics, this broadening can cause scope creep, prompt-injection exposure through retrieved pages, and unexpected data handling without clear user confirmation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The brief schema limits idioma to es | en, which is a natural-language locale restriction. The document does not state that the user can choose the language or explain why only these two locales are permitted, so it may violate language-choice policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This line explicitly requires idioma to be es or en, disallowing other languages. Because the document does not offer a language choice or explain a legitimate region-specific constraint, this is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documented persistence of the generated brief for later use by other skills creates cross-skill data exposure and purpose expansion beyond the immediate task. Even if the content is not highly sensitive by default, retaining and advertising reuse of user-derived data increases the risk of unintended access, chaining, or misuse by other components in the workspace.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs writing a YAML artifact into the workspace automatically, but does not require a user-facing notice or confirmation that a file will be created. Silent writes can surprise users, overwrite existing data if naming collides, and leave residual artifacts that other tools or skills may later consume.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file presents its operational guidance primarily in Spanish, including section headings and instructions, with no indication that users may choose another language. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file’s operational instructions, warnings, and examples are entirely in Spanish, with no indication that the user can choose another language. This can violate language/locale policy when a skill effectively requires one language for use without documenting that constraint or obtaining user opt-in.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file states that some trademarks such as FURminator should remain in the image and only be softened in the video prompt. However, the algorithm applies the NSFW substitution dictionary at Step 1.5 to brief fields and item names/attributes before downstream generation, which contradicts the later documented intent if the same sanitized brief feeds image generation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file contains operational instructions to download results.rawUrl and save it as entregables/infografias/<slug>/02_reel.mp4. That is a file-write behavior affecting local data, but the document does not include any user-facing warning or disclosure about creating or overwriting files.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

Lines L143-L149 instruct the workflow to pause and require explicit user confirmation before image generation. This creates a direct intent-level tension with the manifest language that the skill should always activate when asked to make an infographic, because the documented procedure adds a mandatory confirmation gate rather than proceeding to generation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation instructs the skill to notify the user of each substitution and ask whether to continue, implying a human approval checkpoint. The sample algorithm only transforms the brief and returns it immediately, so the documented interactive confirmation behavior is absent from the described implementation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.