Back to skill

Security audit

investigacion-nicho-formula100k

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed market-research workflow that uses public web and platform data to help validate a content niche.

Install this if you want an agent to perform evidence-based niche research using public web, social, Skool, YouTube, and optional Apify/vidIQ/Tavily data. Before running it, confirm the niche and platforms to research so it does not spend time or API quota on a broader investigation than intended.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The top-level description is broad enough to match many ordinary requests about strategy, market validation, or positioning, which can cause the skill to activate outside its intended niche-research use case. Over-broad activation increases the chance that this skill overrides a more appropriate skill or launches unnecessary browsing/scraping workflows, creating operational and data-handling risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The 'Cuándo activar' triggers are ambiguous and lack exclusion criteria, so common business or content questions could invoke this skill even when the user did not intend a research-heavy workflow. In an agent environment with browser, Apify, and external search tools, ambiguous triggering can lead to unnecessary external queries, higher cost, and collection of third-party data beyond what is needed.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.