other
Warning
- Location
- references/prompts-mockup.md:23
- Finding
- Undisclosed Synthetic Testimonials Presented as Authentic Customer Communications## Vulnerability Details **File Location**: `references/prompts-mockup.md:23-35` **Vulnerability Type**: Deceptive synthetic testimonial generation **Risk Level**: Medium **Complete Snippet**: ```markdown ## 2 · Capturas de testimonio (parecen screenshots reales) Dos rutas — elige según lo que aporte el usuario: **A. El usuario aporta capturas reales de DM/WhatsApp/resultados** → úsalas tal cual (mejor conversión, cero coste). Recórtalas limpias. **B. Generadas** — prompt por testimonio: ``` Realistic smartphone screenshot of a direct-message / results notification. Shows a short message from "[NOMBRE]" celebrating growth: "[TRANSFORMACIÓN]". Instagram/WhatsApp-style UI, believable, casual. Spanish text. Vertical 4:5. No watermark. ``` > Nota: si se generan testimonios, aclarar internamente que son *representativos* y no inventar métricas falsas de personas reales (ver guardarraíl NUNCA inventar data). ``` ### Technical Analysis The Skill provides an operational workflow for generating synthetic testimonials that deliberately resemble authentic direct messages or results notifications. The generation prompt requires a “believable” Instagram/WhatsApp-style interface and explicitly requests that the image contain no watermark. The only disclosure requirement is that generated testimonials be identified **internally** as representative. No instruction requires a visible disclosure on the resulting public landing page. Consequently, prospective customers may be shown generated communications as if they were screenshots of actual customer messages. The guardrail against inventing metrics for real people does not resolve the underlying issue: the generated image still represents that an authentic customer communication or results notification exists when it does not. This is reachable through the normal workflow described in `SKILL.md:68-69`, which directs the agent to generate testimonial images when genuine screenshots are unavailable. ### Attack Path 1. ...[truncated 1332 chars]
- Remediation
- ## Remediation Suggestions 1. Remove instructions to imitate authentic Instagram, WhatsApp, direct-message, or results-notification interfaces. 2. Do not request unwatermarked synthetic testimonials intended to resemble real customer communications. 3. Require generated examples to use a neutral quote-card design that cannot be mistaken for an actual platform screenshot. 4. Add a prominent, visible label directly within every generated asset, such as “Illustrative example — not an actual customer message.” 5. Require documentary proof and explicit authorization before publishing names, photographs, measurable transformations, or attributed testimonial claims. 6. Add a mandatory verification step that distinguishes: - verified testimonials with publication consent; - anonymized but genuine testimonials with retained evidence; and - synthetic illustrations that must be visibly disclosed. 7. Update the final conversion checklist to reject any synthetic social-proof image lacking an audience-visible disclosure.
