Back to skill

Security audit

PostKing · SEO

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for SEO content generation, but it can publish or schedule live articles and run bulk content changes without an explicit final confirmation gate.

Install only if you are comfortable letting the agent operate PostKing SEO tools for your brand. Before use, require the agent to show the exact article, publication target, schedule time, and any bulk edits/deletes/CTA changes, then wait for your explicit approval before publishing or changing live content.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The skill instructs the agent to publish or schedule generated articles and perform other content-modifying actions, but it does not require an explicit confirmation immediately before those live changes occur. In an agentic environment, that omission can cause unintended publication, scheduling, or modification of production content if the user's request is ambiguous or prior context is misinterpreted.

Static analysis

No suspicious patterns detected.