Back to skill

Security audit

Social Media Assistant (via postsyncer.com)

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly a disclosed PostSyncer integration, but it gives an agent broad social-media publishing, moderation, and deletion powers, including connected-account deletion, with only text-based confirmation guidance.

Install only if you are comfortable giving an agent a PostSyncer token that can publish, update, moderate, and delete social-media resources. Use the narrowest token abilities possible, prefer drafts for new automations, and require the agent to show the exact workspace, account, post, comment, label, folder, or media item before approving any publish_now, hide, sync, update, or delete action, especially connected-account deletion.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (11)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

md
1. Create a PostSyncer account at [app.postsyncer.com](https://app.postsyncer.com)
2. [Connect social profiles](https://app.postsyncer.com/dashboard?action=accounts) (Instagram, TikTok, YouTube, X, LinkedIn, etc.)
3. Go to [**Settings → API Integrations**](https://app.postsyncer.com/dashboard?action=settings&section=api-integrations) and create a personal access token with abilities: `workspaces`, `accounts`, `posts`, and (if you use them) `labels`, `campaigns`
4. Add to `.env`: `POSTSYNCER_API_TOKEN=your_token`

## PostSyncer MCP (optional)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
87% confidence
Finding

The skill exposes a destructive media deletion endpoint that could remove assets if an agent is induced to pass attacker-chosen IDs. Although the document says 'confirm first,' the action remains high risk because parameterized destructive operations are available in a general-purpose agent workflow.

Content

Scanner excerpt · SKILL.md (reported line 108)May include surrounding context.

Use multipart/form-data with fields such as workspace_id, file (and optional chunk/chunk metadata if your client uses chunked upload). Not JSON.

Delete Media — DELETE /api/v1/media/{media_id} (confirm first)

bash
curl -X DELETE "https://postsyncer.com/api/v1/media/999" \

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
87% confidence
Finding

Folder deletion is a destructive parameterized operation that can be abused if an agent accepts untrusted IDs or ambiguous user instructions. Prompt-level warnings are not reliable controls, so accidental or induced deletion remains possible.

Content

Scanner excerpt · SKILL.md (reported line 152)May include surrounding context.

-d '{"name": "Renamed folder"}'

text

**Delete Folder** — `DELETE /api/v1/folders/{id}` *(confirm first)*

---

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Post deletion can destroy scheduled content and disrupt business workflows if an attacker or confused user causes the agent to invoke DELETE with a chosen post ID. The context makes this meaningful because the skill is designed for automated social media management, where destructive mistakes have direct operational consequences.

Content

Scanner excerpt · SKILL.md (reported line 254)May include surrounding context.

Only posts that have not been published yet can be updated. Supports the same content[].cover_image shape as create.

Delete Post — DELETE /api/v1/posts/{id} (confirm with user first)

bash
curl -X DELETE "https://postsyncer.com/api/v1/posts/123" \

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
86% confidence
Finding

Comment deletion is another destructive parameterized action vulnerable to misuse if the agent is tricked into targeting the wrong comment ID. In a social-media context, deleting comments can affect moderation history, customer interactions, and auditability.

Content

Scanner excerpt · SKILL.md (reported line 324)May include surrounding context.

-H "Authorization: Bearer $POSTSYNCER_API_TOKEN"

text

**Delete Comment** — `DELETE /api/v1/comments/{id}` *(confirm first)*

```bash
curl -X DELETE "https://postsyncer.com/api/v1/comments/456" \

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Label deletion may seem lower severity than account or post deletion, but it can still damage organization, reporting, or campaign workflows if an attacker manipulates the parameter. Because the skill exposes direct DELETE capability, the risk is real despite the confirmation note.

Content

Scanner excerpt · SKILL.md (reported line 364)May include surrounding context.

md
**Update Label** — `PUT /api/v1/labels/{id}`

**Delete Label** — `DELETE /api/v1/labels/{id}` *(confirm first)*

---

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Connected account deletion is a highly destructive administrative action that can sever publishing capability across platforms if an agent is induced to submit an attacker-chosen account ID. The surrounding skill context increases the danger because these accounts represent access to external social identities and business operations, and a mere textual 'confirm first' warning is not an enforceable control.

Content

Scanner excerpt · SKILL.md (reported line 413)May include surrounding context.

Account Management

Delete Account — DELETE /api/v1/accounts/{id} (destructive, confirm first)

bash
curl -X DELETE "https://postsyncer.com/api/v1/accounts/136" \

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest and top-level description frame the skill as a social media management integration, but the documented analyze-twitter-post capability allows fetching and analyzing arbitrary public X/Twitter URLs unrelated to the user's managed PostSyncer assets. This scope expansion matters because it can cause an agent or user to invoke broader external data collection and AI analysis than the declared purpose suggests, increasing surprise and privacy/compliance risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

List Workspaces — GET /api/v1/workspaces

bash
curl "https://postsyncer.com/api/v1/workspaces" \
  -H "Authorization: Bearer $POSTSYNCER_API_TOKEN"

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 246)May include surrounding context.

Update Post — PUT /api/v1/posts/{id}

bash
curl -X PUT "https://postsyncer.com/api/v1/posts/123" \
  -H "Authorization: Bearer $POSTSYNCER_API_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"content": [{"text": "Updated caption", "media": [42], "cover_image": {"thumbnail": 43}}], "schedule_for": {"date": "2026-03-27", "time": "10:00"}}'

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill advertises content management but also exposes destructive connected-account deletion. Even though the body says 'confirm first,' omission of this high-impact capability from the manifest reduces informed consent and increases the chance an agent could be delegated broader authority than a user expects.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.