Back to skill

Security audit

miniatura-youtube-formula100k

Security checks for vulnerabilities and agentic risk

Overview

This thumbnail-generation skill is mostly purpose-aligned, but it under-discloses sensitive face-image uploads and encourages close copying of another creator's thumbnail style.

Install only if you are comfortable with user selfies and reference images being processed by Gemini or Higgsfield and delivered through Telegram. Add an explicit consent step before uploads, document where images are saved and when they are deleted, avoid direct cloning of another creator's recognizable thumbnail style, and treat provider safety-filter blocks as refusals rather than retry targets.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (20)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 34)May include surrounding context.

md
- **Modo 🅐** → leer `references/clonar-estilo-higgsfield.md` y seguir ese pipeline (subir selfie + referencia, etiquetar FIRST/SECOND image, generar 4 variacion

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 120)May include surrounding context.

md
- **Modo 🅐** → leer `references/clonar-estilo-higgsfield.md` y seguir ese pipeline (subir selfie + referencia, etiquetar FIRST/SECOND image, generar 4 variacion

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 133)May include surrounding context.

md
- **Modo 🅐** → leer `references/clonar-estilo-higgsfield.md` y seguir ese pipeline (subir selfie + referencia, etiquetar FIRST/SECOND image, generar 4 variacion

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 207)May include surrounding context.

md
- **Modo 🅐** → leer `references/clonar-estilo-higgsfield.md` y seguir ese pipeline (subir selfie + referencia, etiquetar FIRST/SECOND image, generar 4 variacion

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 49)May include surrounding context.

md
5. **Estilo de miniatura** — ¿Cuál prefieres? Ver tabla en `references/estilos-plantillas.md`. Si no sabe, usar el **Estilo FORMULA 100K (fondo negro + amarillo

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 209)May include surrounding context.

md
5. **Estilo de miniatura** — ¿Cuál prefieres? Ver tabla en `references/estilos-plantillas.md`. Si no sabe, usar el **Estilo FORMULA 100K (fondo negro + amarillo

Ssd 1

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instruction to 'simplify the description and retry' when safety filters block generation encourages iterative evasion of model safeguards. Even without explicit jailbreak language, it teaches the operator to work around provider-enforced restrictions rather than respect them, which can facilitate prohibited content generation and undermine downstream safety controls.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The workflow directs the agent to upload user selfies and reference images to an external Higgsfield service, but it does not require a clear user-facing disclosure, consent capture, or data-handling explanation before transmission. Because the data includes biometric/face imagery, silent transfer to a third party materially increases privacy and compliance risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The description is written as an instruction for a specialized skill in Spanish and uses the directive 'Usar SIEMPRE' without any indication that the user may choose another language. Under the policy, forcing a specific language without opt-in is a natural-language policy violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Ssd 4

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill explicitly promotes a 'clone style' mode that replicates another creator's thumbnail using the user's face, normalizing close imitation as a standard workflow. In context, this increases the risk of deceptive impersonation, plagiarism, and misleading derivative content, especially because it operationalizes copying a real competitor's visual identity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill directs sending user selfies and reference images to external image-generation providers without an explicit privacy warning or consent flow. Because selfies are highly sensitive personal data, especially when used for identity-preserving generation, third-party transmission creates material privacy and compliance risk if users are not clearly informed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs storing user photos under local directories and delivering outputs via Telegram, but it does not define retention limits, access controls, or deletion behavior. This creates unnecessary exposure of personal images and generated media, particularly where Telegram delivery and on-disk storage may persist beyond the user's expectations.

Content

No source excerpt is available for this finding.

Ssd 4

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The workflow gives step-by-step instructions for reproducing a reference thumbnail while preserving the user's exact identity, making deceptive imitation easier and more repeatable. That combination of identity preservation plus reference-based replication raises misuse risk beyond ordinary editing because it enables near-lookalike outputs modeled on someone else's established content presentation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill claims photos 'are not uploaded anywhere' while instructing that selfies and reference images be sent in API calls to Gemini or Higgsfield. This mismatch is dangerous because it can mislead users and operators about where sensitive biometric images are processed, undermining informed consent and privacy expectations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

The manifest describes a skill for generating and analyzing YouTube thumbnails using user photos and reference images. In addition to image generation, the file directs the agent to verify local binaries and run shell commands (which, magick, convert) for post-processing, which introduces host-level command execution beyond the stated business purpose in the manifest.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The entire skill reference is written as a prescriptive configuration in Spanish, including headings and instructions, with no indication that language is optional or region-specific. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs activation 'SIEMPRE' for broad user requests and reference+selfie combinations, which can cause the agent to enter a style-cloning workflow without sufficient gating, consent checks, or policy review. In this context, aggressive auto-triggering increases the chance of processing sensitive user images and producing imitation content when the user may have intended a safer or more generic thumbnail-editing flow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instruction 'Prompt en INGLÉS y en modo instrucción' imposes a specific language requirement as a rule, rather than offering language choice or explaining a necessary locale constraint. This is a natural-language policy issue because it forces a language preference without user opt-in.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

The documented curl --data-binary upload step is a concrete external transmission of user-provided selfies and reference images to presigned URLs. In the context of a face-based generation workflow, this is sensitive-image exfiltration to a third-party service unless the user has been clearly informed and has consented.

Content

Scanner excerpt · references/clonar-estilo-higgsfield.md (reported line 95)May include surrounding context.

  1. media_upload → files:[{filename:"selfie.jpg",content_type:"image/jpeg"}, {filename:"ref.png", content_type:"image/png"}] → devuelve upload_url + media_id por cada una
  2. curl -X PUT -H "Content-Type: " --data-binary @archivo '<upload_url>' (por cada una)
  3. media_confirm → type:"image", media_ids:[<id_selfie>, <id_ref>]
text
> Tip: si el nombre del archivo tiene caracteres raros (capturas de macOS con espacios/NBSP), cópialo antes a una ruta limpia en el scratchpad (`cp "$(ls | grep <patrón>)" ref.png`).

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The file is written entirely in Spanish and several template placeholders instruct users to produce Spanish text such as "PALABRAS EN MAYÚSCULAS," "ANTES," and "DESPUÉS." Because no alternative language option or justification is provided, this may conflict with a language/locale policy that requires user choice rather than forcing a specific language.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.