Back to skill

Security audit

investigacion-ads-formula100k

Security checks for vulnerabilities and agentic risk

Overview

This is a public paid-ad research skill with some media-retention inconsistencies, but no hidden code, credential use, persistence, or destructive behavior was found.

Install only if you are comfortable with a Spanish paid-ad research workflow that browses public ad libraries, may use paid external scrapers for large batches, and writes local research reports. Before using it, clarify that the agent should not download or store competitor MP4s unless you have a rights/compliance reason; screenshots, ad URLs, and metadata are the safer default.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The file is written as a Spanish-only skill and repeatedly instructs use of fixed Spanish phrasing in user-facing output, such as the doctrinal quotes to use verbatim. There is no indication that the user may choose another language or that the Spanish-only constraint is optional or justified by a region-specific compliance need.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The description says to activate "SIEMPRE" for phrases such as "dame 30 ideas de ads", "guionízame este ad", and "ads de [competidor]". These are broad, natural requests that could match many adjacent skills, especially since the only exclusion given is organic-content research, not other ad-writing or scripting contexts.

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
The skill gives conflicting instructions about handling ad media: early guidance says not to download MP4s, but later output conventions explicitly reference storing downloaded MP4/JPG assets. This inconsistency can cause the agent to retain copyrighted third-party ad creatives unnecessarily, increasing legal/compliance risk and expanding data storage of scraped media beyond the stated safe boundary.

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The Meta Ads Library prompt asks the agent to extract direct image/video URLs even though the skill earlier instructs not to download MP4s. Requesting downloadable asset URLs creates a practical pathway to bypass the no-download rule and facilitates bulk copying of third-party ad creatives, which can violate platform terms or internal handling constraints.

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The TikTok Creative Center prompt explicitly asks for downloadable MP4 URLs while the skill's safety guidance says not to download MP4s. This contradiction encourages collection of downloadable media pointers that can be used for unauthorized retention or redistribution of ad content, undermining the intended public-view-only workflow.

Description-Behavior Mismatch

Low
Confidence
85% confidence
Finding
The manifest and the rest of the skill repeatedly scope the capability to paid ads research in Meta Ads Library and TikTok Creative Center. Line L236 includes 'clockworks~tiktok-scraper' for 'videos orgánicos (no ads)', which exceeds that stated purpose and conflicts with the manifest's instruction not to confuse this skill with organic-content research.

Static analysis

No suspicious patterns detected.