Back to skill

Security audit

Social Media Prompt Generator

Security checks for vulnerabilities and agentic risk

Overview

The package is only a Markdown skill, but it overstates included content and steers users to off-platform payment channels for the advertised material.

Review this skill carefully before installing. It appears technically low-risk to your machine because it has no code or permissions, but its loaded instructions advertise unavailable paid materials and direct users to unaudited external payment/contact channels. Do not send payment or install separately delivered files unless you independently trust the publisher and can verify what you receive.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

other

Note
Location
SKILL.md:25
Finding

Misleading Feature Claims and External Payment Steering

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 25–51
Vulnerability Type: Deceptive promotion and external payment steering
Risk Level: Low

Vulnerable Content

markdown
## What You Get in the Pro Version

The Pro version (available on Telegram: @Cofi_ClawSkill_Bot) includes everything above plus:

- **8 complete templates** (30-day calendar, LinkedIn posts, Twitter threads, Instagram captions, Facebook posts, TikTok scripts, hashtag clusters, content pillars)
- **100+ post templates** across all 5 platforms
- **50+ hashtag clusters** by industry
- **Posting time calculator** — best times per platform
- **Engagement tracker template** with benchmarks
- **3 real examples** (30-day calendar, LinkedIn thread, Instagram campaign)
- **4 Python scripts** (calendar generator, hashtag researcher, post scheduler, engagement calculator)
- **18 files total** of ready-to-use content
- **Lifetime access** — no subscriptions, no extra fees
- **Instant delivery** — pay via crypto or PayPal, receive file immediately

## 🚀 Upgrade to Pro — $4.99 (Lifetime)

**What you get in Pro:**
• All templates + Python scripts + real examples (18 files)
• Lifetime access & updates — no subscription, no extra fees
• Instant delivery after payment

**[💳 Buy Pro $4.99 via PayPal →](https://paypal.me/cofi295/4.99)**

Or pay with **USDT (BEP-20)**:
`0x2927fdf1d705092cf881e1287a71ac56511b550d`

📦 *250+ creators already using our free skills.*

Technical Analysis

The audited package contains only SKILL.md, but its metadata and promotional content claim the availability of templates, examples, calculators, and four Python scripts. None of those resources are included in the reviewed project. The document then directs users to Telegram, PayPal, and a BEP-20 cryptocurrency address to obtain the advertised material.

This is not a confirmed instance of agent instruction hijacking because the text ...[truncated 1597 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove payment solicitation and external sales messaging from the skill's operational instructions.
  2. Ensure the package description accurately reflects only the resources actually included in the repository.
  3. Include the advertised templates and scripts in the package, or remove all claims that they are bundled or immediately available.
  4. Place optional commercial information in clearly separated documentation or marketplace metadata rather than agent-loaded instructions.
  5. Clearly identify external purchases as unaudited and disclose that externally delivered files are outside the package's security boundary.
  6. Prefer a verified distribution channel that provides artifact integrity checks, refund terms, publisher identity, and reproducible versioning.
  7. Subject any subsequently added Python scripts or other executable resources to a separate security review before distribution.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The invocation description is broad marketing copy and example prompts without meaningful scope, guardrails, or trigger constraints. That increases the chance an agent will invoke the skill in loosely related contexts and expose users to embedded upsell/payment content that is unrelated to the requested task.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly advertises off-platform payment flows, external contact via Telegram, a PayPal payment link, and a crypto wallet address, with no safety warning or separation from normal skill functionality. In an agent ecosystem, this can be used to steer users off-platform, solicit payment or financial data, and create phishing/fraud risk under the guise of completing a benign content-generation task.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.