Back to skill

Security audit

viewprinter-social-manager

Security checks for vulnerabilities and agentic risk

Overview

This skill manages a connected ViewPrinter social account and clearly discloses that it can publish posts, read workspace media/posts, and permanently delete stored media.

Install this only if you intend to let ViewPrinter act on connected social accounts. Review post content, destination accounts/groups, and exact scheduled times carefully, and be especially cautious with media deletion because the skill states that deletion permanently erases stored files.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Autonomous Decision Making

Medium
Category
Excessive Agency
Content
"scheduling"
      ],
      "prompt": "The video, caption, @example account and Friday September 18, 2026 at 9am America/Chicago are approved. Schedule it.",
      "expected_output": "uses the existing approval without asking for it again",
      "assertions": [
        "uses the existing approval without asking for it again",
        "resolves the absolute time and account id",
Confidence
75% confidence
Finding
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Autonomous Decision Making

Medium
Category
Excessive Agency
Content
"scheduling"
      ],
      "prompt": "The video, caption, @example account and Friday September 18, 2026 at 9am America/Chicago are approved. Schedule it.",
      "expected_output": "uses the existing approval without asking for it again",
      "assertions": [
        "uses the existing approval without asking for it again",
        "resolves the absolute time and account id",
Confidence
75% confidence
Finding
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Static analysis

No suspicious patterns detected.