Back to skill

Security audit

My goal is to support the community and continue creating more useful tools. If these automations prove to be very helpful to you, or if you see value in what I'm sharing, any donation, no matter how small, is welcome and will allow me to dedicate more time and resources to building new templates and contributing more solutions. https://donate.stripe.com/bJe6oGaaQ9JC1jf15gdwc01 Thank you for your interest, and I hope you find them very useful.

Security checks for vulnerabilities and agentic risk

Overview

This Markdown-only social media skill is mostly coherent, but it frames the agent as having direct publishing access and recommends bulk scraping without clear confirmation or authorization boundaries.

Review this skill before installing. It is not malicious code and ships no executable payload, but users should treat it as capable of affecting public social accounts and should require preview, target account, platform, timing, and final confirmation before any scheduling or posting. Use only data you are authorized to collect, and avoid bulk scraping third-party content unless it complies with platform rules and applicable privacy obligations.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill states it has direct access to a scheduling platform that publishes to major social networks, but it does not warn that outputs or actions could affect live accounts. In context, this is especially risky because users may interact as though they are only brainstorming copy, while the skill framing implies operational authority to publish, creating a real chance of unintended posting, reputational harm, or abuse of connected social accounts.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation description is very broad and can cause this skill to trigger on many generic social-media-related requests, even when the user only wants advice rather than a workflow tied to scheduling or publishing. Over-broad routing is dangerous because the skill claims direct access to publishing infrastructure, so accidental invocation could expose users to unintended high-impact actions or data handling behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly instructs users to scrape 500-1000+ posts from third-party creators using automation tools like Apify and Phantom Buster, which goes beyond ordinary content creation guidance and encourages bulk collection of external platform data. In a skill that may have tool access, this can normalize potentially unauthorized data harvesting, create terms-of-service and privacy risk, and expand the agent's behavior into acquisition of third-party data without clear authorization boundaries.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.