Back to skill

Security audit

CreBee-新媒体多平台分发工具

Security checks for vulnerabilities and agentic risk

Overview

The skill is purpose-aligned for social media automation, but it grants broad posting and analytics access through a long-lived local bearer token without enough scoping, confirmation, or privacy guidance.

Review before installing. Only use this skill with a CreBee gateway you trust, protect bearer tokens as account credentials, and require explicit user approval before publishing, scheduling, canceling tasks, uploading local files, or retrieving fan/audience profile data. Keep media uploads limited to intended files and avoid exposing tokens or analytics in logs or shared transcripts.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:29
Finding

Unauthenticated Issuance of a Long-Lived Privileged Bearer Token

Content
View full analysis
Content-Type: application/json ``` The same token is subsequently used for account enumeration, analytics access, audience-profile retrieval, content publication, publication cancellation, and progress-stream access. ### Technical Analysis The Skill documents `POST /galic/v1/auth/token` as the first authentication step, but it does not specify any existing credential or authorization check required to invoke that endpoint. Consequently, any process capable of connecting to the gateway may be able to mint its own bearer token. The gateway is documented as listening on `127.0.0.1:3456`. Loopback binding limits direct network exposure but is not an authentication boundary. Other local users, compromised applications, malicious browser-mediated requests where applicable, or untrusted Agents operating on the same host may still reach the service. A bearer token grants access based solely on possession. If an unauthenticated caller can mint a long-lived token, the later JWT checks do not establish that the caller was authorized by the account owner ...[truncated 1958 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (23)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill advertises access to fan or audience profiles and analytics but does not warn that these datasets may contain privacy-sensitive or account-sensitive information. In an agent context, this increases the risk of over-collection, over-sharing, or use of personal or behavioral data without clear user awareness or consent boundaries.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file is written as a China-focused social media automation skill and presents its behavior entirely around Chinese platforms and Chinese-language usage, but does not state that this locale is optional or user-selected. Under the policy, language or locale constraints should either be opt-in or clearly justified as a region-specific tool.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly enables batch publishing to multiple social media platforms, which can cause immediate, externally visible changes across connected accounts. Without strong warnings, confirmation requirements, or guardrails around irreversible posting actions, an agent could publish unintended, harmful, or policy-violating content at scale.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file describes content publishing parameters and public-account interaction capabilities without warning that these actions can change live account state and public-facing content. In an automation skill, this increases the risk of unintended posting, draft publication, comment/danmu management misuse, or abusive mass actions if an agent invokes the documented APIs without explicit confirmation and guardrails.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This section documents direct access to fans lists, audience demographics, regional distribution, interest profiles, and related analytics without any privacy, authorization, or data-minimization guidance. In an agent skill meant to automate social-media operations, that omission is dangerous because downstream agents may over-collect or expose sensitive audience data without user consent checks or purpose limitation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The file documents parameters for video, image, and article publishing, including immediate publication when timing is 0, visibility settings, mentions, and downloads. For markdown files, behaviors that can affect user data or system integrity should be disclosed explicitly, but the documentation does not warn that using these parameters may create or schedule public-facing posts on the user's account.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This markdown file describes requests that require bearer tokens and account identifiers, and later exposes endpoints for account analytics and fan demographics. Under the markdown-specific warning rule, the description should warn users that these operations access potentially sensitive account and audience data, but no such warning is present near the authentication or data-access sections.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This documentation exposes analytics and user-portrait endpoints that process account identifiers, message IDs, publication dates, and audience demographic/profile data, but it provides no warning about privacy sensitivity, consent requirements, or data-handling constraints. In an agent skill designed to automate social-media operations, that omission increases the chance that an agent will collect or transmit personal or behavioral data without adequate user awareness or policy checks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document exposes operational endpoints for publishing content and claiming activities that can change account state, but it provides no explicit requirement for user confirmation, authorization checks beyond a bearer token, or warnings about irreversible/account-affecting actions. In an agent skill context, this increases the risk that an automated agent could trigger unintended posts, visibility changes, or activity claims on a user's social-media account without sufficiently informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file describes required API calls that include an Authorization bearer token and accountArgs containing account identifiers, which are privacy- and security-relevant behaviors. The documentation presents these requests as normal usage but does not warn users that sensitive credentials and account data will be sent to a remote endpoint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

该 markdown 文档定义了 videoPath、coverPath、images、content 以及 pubType、timing 等发布相关参数,表明技能可读取本地媒体并执行发布操作。文档虽描述了参数含义,但缺少任何用户警告,未明确提醒这会影响用户数据和外部平台状态,属于可能影响数据与系统完整性的行为说明缺失。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file documents content publishing parameters, including immediate or scheduled posting and visibility controls, but does not clearly warn that invoking the associated publishing capability can create public-facing posts on a user's real social media account. In an agentic automation context, this increases the risk of unintended publication, reputational harm, or misuse if a user or downstream agent does not fully understand the side effects.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The file documents parameters for immediate or scheduled publishing of videos and image posts, including visibility settings, but it does not explicitly warn that using these parameters can publish content to an account and potentially make it public. For markdown skill descriptions, actions that affect user data or account state should include a user-facing warning.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file describes endpoints that retrieve user profile and audience analytics data, including gender, age, city, interests, and audience-source/view-period information, but it provides no warning about privacy-sensitive handling of that data. Under SQP-2 for markdown files, descriptions should warn when behavior can affect user privacy or expose sensitive user/account data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation instructs callers to provide absolute local file paths for videos and covers, but it does not clearly warn that the gateway will read those local files and upload their contents to external social media platforms. In an agentic context, this omission is dangerous because an AI agent may treat arbitrary user- or prompt-supplied paths as safe inputs, causing unintended exfiltration of sensitive local files if path selection is manipulated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This markdown file instructs users to send an Authorization bearer token and accountArgs containing platform/account identifiers, which are sensitive authentication and account-scoping values. The document provides usage details but does not include any warning about protecting tokens, avoiding accidental logging/sharing, or ensuring authorized use of the target account.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

Several endpoints specify the language parameter sLocale with a default of zh_CN, but the document does not state that users may choose another locale or that the locale restriction is required for a region-specific reason. This can constitute a natural-language language/locale policy issue because the skill behavior appears to default to a fixed language without user opt-in.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The request example at L822-L825 shows an empty JSON object, but the response/notes at L827 says body.action is used and that accountArgs is mandatory. This is an active contradiction in the documentation about what the endpoint actually expects, which can mislead callers about the skill's real input requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The natural-language content in this skill file forces a specific language/locale for all users, and there is no indication that Chinese is optional or that the skill is restricted to a China-specific audience for compliance reasons. Under the stated policy, fixed-language behavior without user opt-in can be a locale policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

这是一个 markdown 文件,适用缺少用户警告检查。该段明确要求在请求头中携带 Authorization: Bearer <token>,并在请求体中提交 accountArgs,但没有任何关于凭据处理、敏感信息暴露或仅在受信环境中使用的提示,可能导致用户在不了解敏感性的情况下调用接口。

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file documents use of an Authorization bearer token and required accountArgs fields, which involve sensitive authentication and account-identifying data. The document provides usage instructions but does not include any warning about protecting tokens, avoiding accidental disclosure, or using authorized accounts only.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This markdown file documents that all requests must include a bearer token and accountArgs containing platform and account identifiers, but it does not include any warning that these requests transmit authenticated account data to the service. For markdown files, missing warnings about behaviors affecting privacy or sensitive account access should be flagged when the description omits user-facing disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This markdown file describes required use of a bearer token and account identifiers for all requests, which implies handling authentication material and account-scoped data. The document does not include any warning about protecting tokens, using authorized accounts only, or the privacy implications of querying account analytics.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.