Back to skill

Security audit

rutina-maestra-formula100k

Security checks for vulnerabilities and agentic risk

Overview

This skill is a content-automation setup helper, but it has contradictory instructions about email collection and scheduling while persisting personal profile data and creating recurring automations.

Review before installing. The skill appears to be a local configuration and scheduling helper, not an exfiltration or malware artifact, but users should be aware it may store contact/profile data and create recurring automations. The publisher should resolve the Telegram-versus-email and /schedule contradictions, add explicit consent and deletion guidance for cerebro/f100k-config.json, and narrow the trigger language before this is treated as routine install material.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (9)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger includes a broad catch-all phrase such as 'cualquier intención de automatizar su rutina de contenido,' which can cause the skill to activate in situations where the user did not clearly intend persistent automation setup. Because this skill collects profile/configuration data and writes persistent state, overbroad invocation raises the risk of accidental data collection and unintended automation changes.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill states that OpenClaw does not support /schedule, but later instructs use of /schedule and /schedule list. This inconsistency can cause an agent to invoke unsupported or mis-mapped tooling, potentially creating failed automations, unintended command routing, or unsafe fallback behavior in environments that interpret slash commands differently.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file explicitly says not to ask for email, but later instructs the agent to request and persist an email address. This kind of internal contradiction is dangerous because it increases the chance that agents collect personal data users were told would not be needed, undermining privacy expectations and creating unauthorized retention.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill’s documented behavior contradicts its stated Telegram-only delivery model by collecting and later using an email address for digests and test output. This can misroute user data, cause unexpected storage of contact information, and break user consent expectations around where notifications and personal data will be sent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructions, prompts, and invocation guidance are entirely in Spanish and direct the interaction flow in that language, with no opt-in or alternative locale offered. This is a natural-language policy concern because it imposes a language preference across the whole skill without user choice or an explicit region-specific justification.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly directs the agent to trust and reuse previously stored user configuration and profile details from persistent memory across automations. Reusing persisted profile data without revalidation or visibility to the user can lead to stale, excessive, or unauthorized use of personal information in future automated actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description does not provide a clear privacy warning before collecting and storing user contact details, niche information, handles, schedule preferences, and voice profile data. Without an upfront notice, users may not understand that their personal and behavioral data will be persisted and reused across automations.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill instructs the agent to collect and persist personal/contact details and behavioral profile data, including social handles, timezone, schedule preferences, and voice profile, in a local memory file for later automated use. Persistent storage of user profiling data without clear minimization, consent, retention, or access controls increases privacy risk and the blast radius if the local memory is exposed or reused improperly.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The onboarding header and introductory text both describe an 8-question flow. The file then defines Q1 through Q9, including module selection as a ninth question, which is a straightforward contradiction in the skill’s own instructions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.