Back to skill

Security audit

Fuxux Social Manager

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Fuxux social media manager, but installing it gives an agent power to use your Fuxux API key to schedule, publish, edit, and delete managed posts.

Install only if you intend to let an agent manage Fuxux-connected social accounts. Keep the FUXUX_API_KEY private, rotate it if exposed, review generated content before broad posting, and be aware that the MCP bridge relies on an unpinned Node package in the provided examples.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · .clawhubignore (reported line 1)May include surrounding context.

text
.env
.env.*
*.zip
.DS_Store

MCP Config Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill accesses MCP server configuration files (mcp.json). MCP configs contain server URLs, authentication tokens, and tool definitions — reading them allows the skill to discover and potentially abuse other tool integrations.

Content

Scanner excerpt · README.md (reported line 10)May include surrounding context.

md
| File | Purpose |
|------|---------|
| **[SKILL.md](./SKILL.md)** | Agent instructions + ClawHub YAML frontmatter (`metadata.openclaw`) — the only file ClawHub requires |
| **[examples/openclaw-mcp.json](./examples/openclaw-mcp.json)** | Copy-paste MCP config (`mcp-remote` + Bearer token) |

## Quick start (users)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 289)May include surrounding context.

8. Delete a scheduled post

http
DELETE /api/posts/{post_id}

Works with your fx_live_ API key. A draft or scheduled post is removed and will never publish. For an already-published post this deletes only Fuxux's record — it does not remove the post from the social platform. Returns 409 while the post is mid-publish; wait a moment and retry.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 411)May include surrounding context.

md
| `POST /api/media/upload` | ✅ |
| `GET /api/posts/{id}` | ✅ |
| `PATCH /api/posts/{id}` | ✅ |
| `DELETE /api/posts/{id}` | ✅ |
| `POST /api/ai/generate` | ✅ |

When a route returns `401` with an API key, tell the user to complete the action in the Fuxux web app or use MCP tools that wrap supported routes.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The skill installs and invokes mcp-remote via npx without pinning an exact package version or integrity hash. That creates a supply-chain risk: a future malicious or compromised package release could execute arbitrary code in the agent environment and access sensitive data such as FUXUX_API_KEY or workspace files.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This manifest defines an MCP server endpoint and command but provides no description of when or in what context it should be invoked. For manifest files, missing specificity on trigger scope or constraints can lead to unintended activation because there are no explicit boundaries or exclusions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.