Back to skill

Security audit

Content Automation

Security checks for vulnerabilities and agentic risk

Overview

This skill is a content automation helper, but it asks users to install and run an unpinned external project that can publish to social accounts using configured credentials.

Install only if you intend to use MoneyPrinterV2 for social-media/content automation. Review the external repository and dependencies first, pin a known commit, use an isolated virtual environment, keep credentials out of broadly readable config files, and require explicit confirmation before any upload, scheduled post, affiliate tracking, or account-affecting action.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:15
Finding

Unpinned External Repository and Unverified Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 15–28
Vulnerability Type: Supply-chain risk through mutable external code and unverified Python dependencies
Risk Level: Medium

Vulnerable Code

bash
# Clone repository
git clone https://github.com/FujiwaraChoki/MoneyPrinterV2.git
cd MoneyPrinterV2

# Requires Python 3.12+
python --version

# Create virtual environment
python -m venv venv
source venv/bin/activate  # Windows: .venv\Scripts\activate

# Install dependencies
pip install -r requirements.txt

Technical Analysis

The Skill directs users to clone the current default branch of an external Git repository and install the dependencies declared by that repository. It does not pin the repository to an audited commit or signed release, verify the downloaded source code, or require cryptographic hashes for Python packages.

As a result, the effective code and dependency set can change after this Skill has been reviewed. A compromised upstream repository could modify application code or requirements.txt. A compromised or malicious dependency could also execute code during package installation through build-system hooks or when the installed application is subsequently launched.

The packaged quick-start script repeats these installation instructions at scripts/content-automation-quickstart.py:30-36, but it only prints them and does not invoke git, pip, or a shell directly.

Attack Path

  1. An attacker compromises the upstream repository, its default branch, a referenced Python package, or a transitive dependency.
  2. The attacker adds malicious application code, changes dependency specifications, or publishes a malicious package version accepted by requirements.txt.
  3. A user follows the Skill instructions and clones the mutable default branch.
  4. The user runs pip install -r requirements.txt.
  5. Malicious package build or installation logic executes, or the mal ...[truncated 947 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the external repository to a specific audited commit hash or a cryptographically signed release rather than cloning an unspecified default branch.
  2. Document the expected commit hash and require users to verify it before installation.
  3. Replace loosely resolved dependencies with a lock file containing exact package versions and cryptographic hashes.
  4. Install dependencies using hash enforcement, such as pip install --require-hashes -r requirements.lock.
  5. Review all direct and transitive dependencies and use automated vulnerability and provenance scanning.
  6. Prefer vendoring the minimum required implementation into the Skill package so the audited code matches the code that users execute.
  7. Install and run the external project in an isolated, least-privileged environment without access to unrelated credentials or sensitive host files.
  8. Avoid placing API and platform credentials in broadly readable plaintext configuration files; restrict file permissions and use an appropriate secret-management mechanism.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The declared purpose frames the skill as benign content assistance, but the actual documented behavior heavily centers on setting up and operating an external repository with automation features, including upload/posting workflows. This mismatch can mislead users or orchestrators into invoking a skill under a lower-risk assumption than its real operational footprint warrants.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 49)May include surrounding context.

md
},
  "youtube": {
    "enabled": false,
    "client_secrets_file": "client_secrets.json"
  },
  "affiliate": {
    "enabled": false,

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill documents shell commands (git clone, pip install, bash scripts/...) but does not declare any explicit tool scope or permissions boundary. In an agent setting, this can lead to unsafe execution expectations, making it easier for the skill to trigger repository fetches or local command execution without a clearly constrained authorization model.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The activation description is broad enough to match many ordinary content-related requests, increasing the chance the skill is invoked in contexts where users did not intend repository setup, scripting, scheduling, or publishing operations. Overbroad triggers are dangerous in agent systems because they expand the surface for unintended tool use and risky automations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest scopes the skill to content generation, video script creation, and scheduling/publishing management. The documented configuration for affiliate settings such as an Amazon tag introduces monetization/tracking capability that is not explained as part of the skill's purpose and is unrelated to the stated core functions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The markdown describes scheduled posting and automation of account-affecting actions without prominent warnings, approval gates, or confirmation requirements. In practice, this can cause accidental publication, policy violations, or misuse of linked social accounts if an agent follows the documentation too literally.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation includes direct upload/publishing automation (upload_video.sh, scheduled_post.sh) even though the skill is presented primarily as content-creation assistance. External publishing actions can affect user accounts, public reputation, and platform compliance, so hiding them behind a softer description increases the risk of unintended high-impact actions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code file contains natural-language strings and comments exclusively in Chinese, including the title, instructions, and warnings. The policy requires flagging language or locale constraints when the skill forces a specific language without user opt-in, and no alternative language option is presented here.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.