Back to skill

Security audit

reel-faceless-f100k

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a disclosed faceless-video workflow, but it can use local facial photos and send them to an external video service without a dedicated consent step.

Install only after the publisher removes the `cerebro/fotos` avatar path for this faceless skill or adds a clear opt-in that names the exact photo, recipient, purpose, and retention expectations before upload. Operators should also pin or preinstall external tooling and clarify that OpenClaw mode only produces the mute base video plus separate voice and PNG assets.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
reference/clip-director.md:82
Finding
Automatic Upload of Local Facial Photographs to an External Service## Vulnerability Details **File Location**: `reference/clip-director.md:82-86` **Vulnerability Type**: Unauthorized external disclosure of biometric-identifying images **Risk Level**: Medium **Complete Snippet**: ```markdown - **Con avatar** (segmento sobre el usuario, su logro, su historia): subir foto de `cerebro/fotos` (media_upload → PUT → media_confirm), pasar `medias`, y cerrar el prompt con `, character inspired by the reference image provided, maintain facial features from reference`. Descripción de persona: la descripción física de la usuaria sacada de SUS fotos (nunca un ejemplo fijo). ``` ### Technical Analysis The Clip Director instructs the Agent to select a photograph from the local `cerebro/fotos` directory and upload it through Higgsfield's media-upload workflow whenever a segment concerns the user, their achievements, or their story. The transcript controls whether this classification activates, but the instructions do not require the Agent to: - obtain explicit consent for uploading a facial image; - disclose the external destination and processing purpose; - display and confirm the exact selected file; - restrict selection to an image explicitly supplied for the current task. The general plan-confirmation step does not expressly disclose this image transfer. The behavior also conflicts with the faceless scope stated in `SKILL.md:28-30`, where the user is told that they never appear on camera and that the video uses generated visuals. This is high-risk privacy behavior rather than proven malicious exfiltration: the documented destination is the video-generation service used by the Skill, and the project contains no evidence of a covert recipient or deliberate theft. ### Attack Path 1. The user requests a faceless reel and supplies or records a transcript containing a personal achievement or story. 2. The Clip Director classifies that portion as a segment “about the user.” 3. The Agent accesses `cerebro/fotos`, a local photo c ...[truncated 1118 chars]
Remediation
## Remediation Suggestions - Remove automatic discovery and selection of images from `cerebro/fotos`. - Default all faceless workflows to non-personal cinematic B-roll with no reference media. - Require the user to explicitly opt in before any avatar or face-preserving generation. - Before upload, present the exact local file path, a preview or unambiguous description, the external recipient, the processing purpose, and the applicable retention implications. - Require a dedicated confirmation immediately before `media_upload`; general approval of the visual plan must not authorize sensitive-image transfer. - Restrict uploads to a file explicitly selected or supplied by the user for the current task. - Record the consent decision in `plan.json` without storing additional sensitive image data. - If consent is declined or cannot be established, omit `medias` and generate an abstract or non-identifying visual. - Align `SKILL.md` with the implementation by clearly distinguishing “not filmed on camera” from the use of an uploaded facial reference, or prohibit facial references entirely to preserve the advertised faceless behavior.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (12)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill instructs the agent to collect, store, and process the user's voice recording, but it does not clearly state retention, access, deletion, or privacy expectations. Voice recordings are sensitive personal data, so silent handling increases the risk of privacy violations, over-retention, and user surprise.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill sends user-derived content and prompts to external AI/video services (for transcription, image/video generation, and related processing) without a clear disclosure. That can expose personal or proprietary content to third parties and create compliance issues if users are not informed or given a choice.

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
The OpenClaw-specific section says composition must be limited to mute clip concatenation, but later instructions describe overlaying graphics and mixing voice/music into a final rendered reel. Contradictory execution guidance in an agent skill is dangerous because the model may choose the broader, more powerful path, causing unintended media processing, data handling, or tool usage beyond the constrained mode.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding
`uvx --from mlx-whisper` pulls and executes code from an external package source without a pinned version. In a security-sensitive automation context, this can lead to execution of malicious or incompatible code if the upstream package changes or is compromised.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding
The skill invokes `npx hyperframes` without pinning an exact package version, which allows whatever version is current at execution time to be fetched and run. In an agent environment, this creates a supply-chain risk: a compromised upstream release or breaking update could execute unreviewed code or alter behavior unexpectedly.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding
This second `npx hyperframes` usage has the same issue: it resolves and executes an unpinned package at runtime. That exposes the agent to supply-chain compromise and non-deterministic behavior, especially problematic for automated systems that may run unattended.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The file states that prompts must be in English for Higgsfield, which imposes a language constraint. Because no user opt-in, alternative language handling, or clear justification is provided, this is a natural-language policy violation under the locale/language rule.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
The faceless skill’s stated purpose is to create videos where the user never appears on camera, yet the shared Clip Director includes logic to upload and process photos from `cerebro/fotos` to generate avatar-based visuals. That expands the data scope to biometric/personal image processing without clear necessity for this skill, creating avoidable privacy risk and potential misuse of sensitive personal media.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The instructions direct the agent to use the user’s photos to generate media and derive a physical description from those photos, but there is no explicit user-facing notice or consent flow for handling personal image data. This is dangerous because it can surprise users, exceed their expectations for a faceless workflow, and create privacy/compliance issues around collection and transformation of personal imagery.

Intent-Code Divergence

Low
Confidence
90% confidence
Finding
L015 states that onboarding and installation steps should be skipped for this server deployment. However, L213 instructs `brew install uv` as an error recovery path, which conflicts with the stated 'does not apply' guidance rather than merely omitting detail.

Natural-Language Policy Violations

Low
Confidence
96% confidence
Finding
The instruction mandates 'Español neutro' and explicitly forbids other regional variants such as 'vos/tenés/acá'. This is a natural-language locale constraint applied by default, with no indication that the user can choose their preferred dialect or opt in to the restriction.

Description-Behavior Mismatch

Low
Confidence
78% confidence
Finding
The manifest describes producing a standalone faceless 9:16 reel assembled from generated clips, cards, and voiceover planning. This file also defines a separate `support` mode with 16:9 support clips, keyword anchoring to the user's spoken footage, and safe-zone overlays for not covering the user's face, which is outside the manifest's claimed behavior for this skill.

Static analysis

No suspicious patterns detected.