Back to skill

Security audit

PostKing · Landing Pages

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent PostKing landing-page workflow guide, with expected public publishing and domain actions that users should review before use.

Before installing, understand that this skill can guide an agent to publish or unpublish pages, delete versions or domains, rename side-page URLs, and import external pages through PostKing. Ask the agent to confirm the exact page, URL, domain, and consequence before public, destructive, or external-import actions.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The skill documents publish, delete, restore, unpublish, and in-place state-changing operations, but it does not impose a consistent confirm-before-destructive-action rule across them. In an agent setting, this increases the risk of accidental live publication, deletion, rollback, or URL-breaking changes being executed from ambiguous user requests, especially because some actions are immediate and some affect public content.

Missing User Warnings

Low
Confidence
78% confidence
Finding
The skill encourages server-side fetching of external URLs for side-page import and supports custom-domain registration, but it does not clearly warn that third-party content and domain data will be transmitted to PostKing infrastructure. This can surprise users handling private URLs, staging sites, or sensitive domain ownership workflows, creating avoidable privacy and data-handling risk.

Static analysis

No suspicious patterns detected.