Back to skill

Security audit

publicar-ig

Security checks for vulnerabilities and agentic risk

Overview

The skill is not clearly malicious, but it should be reviewed because it can upload local media to a public GitHub repo and publish to Instagram with some scoping and approval ambiguities.

Install only if you are comfortable with media being uploaded to a public GitHub repository controlled by your authenticated GitHub account before Instagram posting. Verify the repo owner and name before first use, avoid sensitive or private media, and require a specific preview-bound confirmation before allowing any post.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill says assets must only be published through the user's own connected GitHub account, but later instructs creation/cloning of repositories using hardcoded operator-owned names like '/ig-assets' and 'formula100k-ig-assets'. This creates a direct confidentiality and ownership risk because user media may be uploaded to infrastructure not controlled by the user, contradicting the stated trust boundary.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly says to never use a repo or storage that is not the user's, then later tells the agent to create and use a specific operator/organization repository. This contradiction undermines a core privacy guarantee and can lead to unauthorized public disclosure of media intended only for the user's publishing flow.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger condition uses an expansive catch-all that activates on 'any variation' combining media with intent to post to Instagram. For a skill that can publish externally, overly broad invocation rules increase the risk of accidental activation and unintended preparation of public posting actions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The introductory guidance says that if neither Composio nor Zapier is connected, the agent must not publish and should instead send files and caption for manual upload. However, the main pipeline is written as though GitHub push and Zapier publication are the normal path, which increases the chance that an implementation follows the pipeline without enforcing the earlier safety gate.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The workflow depends on pushing media to a public GitHub repository before posting, but the user-facing description does not prominently and consistently warn that the assets become publicly accessible at that stage. This can expose unpublished or sensitive media to anyone with the URL or repository access pattern before Instagram publication occurs.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill metadata requires an explicit ✅ via Telegram after showing the full preview, but the operational steps weaken that control by accepting generic confirmations like 'sí', 'ya', or 'dale' without binding the approval to Telegram or the exact previewed content. In a chatty agent environment, this can cause unintended posting if a loosely related affirmative message is misinterpreted as authorization.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

These instructions mandate a particular linguistic variant and explicitly prohibit Argentine Spanish, with automatic rewriting based on stored preferences. That is a locale/language policy constraint imposed by default rather than offered as a user choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.