Back to skill

Security audit

Autopostonline Agents

Security checks for vulnerabilities and agentic risk

Overview

This docs-only skill clearly teaches agents to use an external social publishing API, including live posting, but the behavior is disclosed and framed around owner-approved rules.

Install only if you intend to let an agent work with AutoPostOnline. Start in safe mode, grant the API key only through a secret manager or environment variable, restrict the campaign rules and allowed channels, and revoke or rotate the key if the agent no longer needs publishing access.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The guide presents the agent as a general-purpose autonomous publishing operator with broad capabilities, but it does not define concrete activation gates, approval checks, or hard limits for when live actions may occur. In a skill that can post to human-owned social accounts, this ambiguity increases the chance of unauthorized publishing, misuse of connected accounts, or operation outside user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly allows uploads, scheduling, publishing, recurring campaigns, and analytics retrieval on live accounts without an equally explicit warning about real-world effects, privacy implications, and the need for user authorization. Because these actions can affect public brand channels and expose business performance data, the lack of prominent safeguards makes accidental or overly broad execution materially more dangerous in this context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README actively promotes autonomous social publishing and provides operational guidance for approval-free posting, but it does not prominently warn about risks such as accidental public posting, policy violations, reputational damage, or misuse of API credentials. In this context, omission of safety guidance matters because the skill is explicitly designed for autonomous agents acting on human-owned social accounts, increasing the chance that users deploy it in high-impact public workflows without adequate guardrails.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document explicitly instructs the owner to hand an API key to an agent for autonomous publishing, but it does not warn about the security implications of granting a reusable credential that can post to connected social accounts. In this context, a leaked, over-scoped, or misused key could enable unauthorized posting, reputational damage, spam, or continued account access beyond the intended campaign boundaries.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation promotes autonomous social publishing and provides operating guidance for agents, but it does not clearly warn about the real risks of unintended public posting, misuse of connected accounts, or reputational and compliance harm from automation errors. In this context, the omission matters because the skill is explicitly designed to let agents publish to external public channels using a single API key, which increases the chance that users will enable risky behavior without adequate safeguards.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest explicitly markets 'Autonomous social publishing infrastructure for AI agents' but does not define any trigger boundaries, approval requirements, or limits on when an agent may draft, schedule, or publish content. In a capability set that includes direct publishing and campaign workflows, this ambiguity increases the chance of unintended autonomous actions, abuse by connected agents, or misaligned posting behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest exposes impactful capabilities such as upload_media, schedule_posts, publish_posts, retrieve_analytics, and autonomous_campaign_workflows, yet provides no user-facing warnings, confirmation requirements, or safety restrictions for these actions. Because these operations can directly affect public-facing accounts and brand reputation, the lack of explicit safeguards makes accidental or unauthorized mass posting materially more dangerous.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.