Back to skill

Security audit

PostKing · Competitor Intel

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward PostKing competitor-management guide, with one safety note around confirming deletions before use.

Install only if you intend to let your agent manage competitor records in PostKing. Before deletion or bulk import/refresh, confirm the brand, target IDs or domains, and expected impact in plain language.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
91% confidence
Finding
The skill documents a destructive CLI operation (`pking competitors delete <id> --destructive`) without any adjacent warning, confirmation guidance, or explanation of removal impact. In an agent-skill context, this increases the chance that an automated agent or inattentive operator could remove competitor records unintentionally, causing loss of tracked intelligence or workflow disruption.

Static analysis

No suspicious patterns detected.