Back to skill

Security audit

ContentStudio

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent ContentStudio automation helper, but it needs Review because it installs an unpinned external CLI that receives sensitive credentials and can perform high-impact social, team, and reporting changes.

Install only after reviewing or pinning the exact contentstudio-cli version and skill source you intend to trust. Use a dedicated ContentStudio API key with the least permissions needed, confirm the active workspace before any write, keep dry-run previews for posting, deletion, inbox replies, and report/share-link changes, and avoid unattended bulk-delete or auto-approval scripts unless you have separate review and rollback controls.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:10
Finding

Unpinned and Unauditable Executable Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:10-18; additional instances in README.md:5-8, README.md:24-30, and README.md:40-44
Vulnerability Type: Unpinned third-party executable dependency
Risk Level: Medium

Vulnerable Code

SKILL.md:10-18:

bash
## Install ContentStudio CLI if it doesn't exist

```bash
npm install -g contentstudio-cli
# or
pnpm install -g contentstudio-cli

npm release: https://www.npmjs.com/package/contentstudio-cli contentstudio-agent github: https://github.com/contentstudioio/contentstudio-agent

text

`README.md:5-8`:

```bash
**Install as a skill:**
```bash
npx skills add contentstudioio/contentstudio-agent
text

`README.md:24-30`:

```bash
### From npm (recommended)

```bash
npm install -g contentstudio-cli
# or
pnpm install -g contentstudio-cli
text

`README.md:40-44`:

```bash
```bash
npx skills add contentstudioio/contentstudio-agent
text

### Technical Analysis

The Skill instructs an agent or operator to install and execute the current registry version of `contentstudio-cli` globally. It also invokes an external package through `npx` without pinning a commit, package version, or integrity digest.

The audited project contains only documentation and does not include the CLI source code, `package.json`, a lockfile, or a bundled executable. Therefore, the effective executable payload cannot be verified from this artifact and may change after the Skill has been reviewed. The claimed credential redaction, TLS validation, endpoint handling, file permission enforcement, and dry-run protections consequently cannot be independently confirmed.

This is especially significant because the installed CLI is expected to receive:

- `CONTENTSTUDIO_API_KEY`
- A Bluesky app password
- Connected social-account and workspace identifiers
- Customer inbox messages and contact details
- Local files selected for media up
...[truncated 2689 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the CLI version

    • Replace mutable installation commands with an exact audited version, for example:
      bash
      npm install -g contentstudio-cli@1.5.0
      
    • Do not use version ranges or implicit latest.
  2. Verify package integrity

    • Publish and document the expected npm integrity digest.
    • Verify the downloaded package tarball against that digest before installation.
    • Sign releases and publish verifiable provenance or build attestations.
  3. Pin Skill retrieval

    • Pin npx skills add to a reviewed package version or immutable Git commit.
    • Avoid retrieving mutable repository branches during automated installation.
  4. Include auditable implementation materials

    • Include the CLI source, package.json, lockfile, and build configuration in the review artifact.
    • Ensure the distributed npm bundle can be reproducibly built from the audited source.
  5. Avoid global installation

    • Prefer project-local installation with a lockfile.
    • Execute the pinned binary through a constrained package script or an explicitly versioned npx invocation.
    • Run it in a sandbox or container with access only to required files and environment variables.
  6. Minimize credential scope

    • Use a dedicated API key with only the workspaces and operations required for the task.
    • Do not expose unrelated environment variables to the CLI process.
    • Rotate the API key and Bluesky app password after any suspected package compromise.
  7. Constrain network destinations

    • Enforce an allowlist for the production ContentStudio API hostname.
    • Disable or tightly restrict CONTENTSTUDIO_BASE_URL and --base-url overrides in production agent environments so authenticated traffic cannot be redirected to an attacker-controlled endpoint.
  8. Harden package execution

    • Disable dependency installation scripts where feasible ...[truncated 222 chars]
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (30)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · CHANGELOG.md (reported line 371)May include surrounding context.

md
### posts:update, approval workflows, LinkedIn polls & collaborators

- New `accounts:remove <account_id>` command — `DELETE /workspaces/{w}/accounts/{account_id}` disconnects a social account (`account_id` is the account's `_id` from `accounts:list`). Requires the `save_social` permission (403 otherwise); 404 when the account isn't found, 422 when removal fails. Carries `--dry-run` like the other mutating commands.
- New `posts:update <post_id>` command — PUTs `/workspaces/{w}/posts/{post_id}` with the **same body/flags** as `posts:create` (shared option set + body builder). The backend rejects the update (422) once the post is `published` or `processing`.
- New `approval-workflows:list` command (GET `/workspaces/{w}/approval-workflows`) — lists `{ _id, name, is_default, levels[] }`; use `_id` as `--approval-workflow-id`.
- `posts:create` / `posts:update` new shortcut flags:

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 451)May include surrounding context.

md
| Command | Purpose |
|---------|---------|
| `accounts:remove <account_id> [--dry-run]` | Remove (disconnect) a social account (`DELETE /workspaces/{w}/accounts/{account_id}`) |

- `account_id` is the account's `id` from `accounts:list`.
- Requires the `save_social` permission — callers without it get 403.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · CHANGELOG.md (reported line 398)May include surrounding context.

md
- Resolves a docs/metadata mismatch: the frontmatter already declared `requires.env: CONTENTSTUDIO_API_KEY`, but the body only documented `auth:login`, so OpenClaw operators were left blocked with no instruction on how to satisfy the gate.
- No CLI source-code changes — the CLI already reads `CONTENTSTUDIO_API_KEY` from the environment (`src/config.ts`).

### write commands for workspaces/labels/campaigns/team + posts:create fixes

- Fixed `posts:create`: now emits top-level `content_category_id` and no longer forces `--account` when `--content-category-id` is supplied (content-category posts derive accounts from the category — previously 422'd). Added `--content-category-id`.
- `posts:create` now normalizes `--scheduled-at` to the backend's `YYYY-MM-DD HH:MM:SS` (UTC) format, and gained parity flags `--label` (repeatable, max 20), `--campaign-id`, `--approver` (repeatable) + `--approve-option` + `--approval-notes`, and `--facebook-background-id`. `--publish-type` now also accepts `now`.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The README instructs users to run npx skills add contentstudioio/contentstudio-agent without pinning a version or commit. This creates a supply-chain risk because a future malicious or compromised release of the skills package or referenced skill could be fetched and executed implicitly at install time. In an AI-agent context, this is more dangerous because it normalizes one-command installation into agent environments with broad local access.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

This installation instruction again uses unpinned npx skills add, exposing users to remote code or content changes outside the repository snapshot they reviewed. Because npx resolves the latest package by default, any compromise upstream can alter the installed skill or installer behavior without warning.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The agent-focused section repeats an unpinned npx skills add command, which is especially risky because it targets autonomous tooling environments. A changed upstream package or skill definition could be installed into agent skill directories and later invoked with user data or local filesystem access.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The claim that the agent will 'automatically know when to use' the CLI encourages broad autonomous invocation without clear scoping or user confirmation. In a skill that can publish posts, reply to customers, delete content, and manage schedules, this increases the risk of unintended execution triggered by ambiguous prompts or over-eager tool selection.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The bulk-delete draft workflow shows an automated destructive loop deleting all matching posts without an explicit safety warning, confirmation step, or dry-run example. In practice, users or agents may adapt this snippet directly and erase large amounts of content due to filter mistakes, stale variables, or wrong workspaces.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
89% confidence
Finding

The documented 'auto-approve posts from a trusted creator' workflow delegates approval decisions to an automated rule based solely on creator identity. In a system that can publish customer-facing content, this weakens review controls and can allow compromised accounts, abusive insiders, or prompt mistakes to push unreviewed material live.

Content

Scanner excerpt · README.md (reported line 1293)May include surrounding context.

done

text

### 5. Approval pipeline — auto-approve posts from a trusted creator

```bash
#!/bin/bash

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
90% confidence
Finding

The script line performs the actual automatic approval of pending posts, enabling state-changing decisions without human confirmation. In context, that can directly affect public communications and brand reputation, making unintended or malicious approvals materially impactful.

Content

Scanner excerpt · README.md (reported line 1302)May include surrounding context.

contentstudio --json posts:list --status pending_approval --per-page 50
| jq -r --arg u "$TRUSTED_USER_ID" '.data[] | select(.created_by == $u) | .id'
| while read id; do contentstudio --json posts:approve "$id" --comment "auto-approved (trusted creator)" done

text

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · README.md (reported line 1351)May include surrounding context.

falls back to ~/.config/contentstudio/config.json

text

File mode `0600`, parent dir `0700` — never world-readable.

Format:
```jsonc

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README states analytics are read-only, but later documents commands that create, run, pause, resume, disable, enable, and delete reports, schedules, share links, and competitor configurations. This mismatch can mislead users or agents into granting broader trust than warranted, increasing the chance of unintended state-changing operations in supposedly safe/reporting workflows.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 1478)May include surrounding context.

md
contentstudio reports:delete <report_id>                                            # Remove

# Analytics — recurring schedules
contentstudio report-schedules:create --name "Monthly" --platform-type facebook \
  --frequency monthly --accounts <id> --emails a@b.com                              # Provision once
contentstudio --json report-schedules:list                                          # All schedules
contentstudio report-schedules:get <schedule_id>                                    # Last run / next run

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 78)May include surrounding context.

md
name: contentstudio
description: ContentStudio is a tool to schedule social-media posts, manage the social inbox, and pull performance analytics across Facebook, LinkedIn, Twitter/X, Instagram, YouTube, TikTok, Pinterest, Threads, Tumblr, Bluesky, and Google Business Profile. Use when the user wants to list/create/delete/approve posts, find the best time to post, generate or edit images with AI, read and reply to DMs, comments and reviews, manage media, audit workspaces, accounts, campaigns, labels, categories, or team-members, or pull analytics reports (top posts, engagement, impressions, follower growth, AI insights, etc.) on their ContentStudio account.
version: 1.5.0
homepage: https://api.contentstudio.io/guide
metadata: {"openclaw":{"emoji":"📅","requires":{"bins":["contentstudio"],"env":["CONTENTSTUDIO_API_KEY"]}}}
---

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 1308)May include surrounding context.

md
name: contentstudio
description: ContentStudio is a tool to schedule social-media posts, manage the social inbox, and pull performance analytics across Facebook, LinkedIn, Twitter/X, Instagram, YouTube, TikTok, Pinterest, Threads, Tumblr, Bluesky, and Google Business Profile. Use when the user wants to list/create/delete/approve posts, find the best time to post, generate or edit images with AI, read and reply to DMs, comments and reviews, manage media, audit workspaces, accounts, campaigns, labels, categories, or team-members, or pull analytics reports (top posts, engagement, impressions, follower growth, AI insights, etc.) on their ContentStudio account.
version: 1.5.0
homepage: https://api.contentstudio.io/guide
metadata: {"openclaw":{"emoji":"📅","requires":{"bins":["contentstudio"],"env":["CONTENTSTUDIO_API_KEY"]}}}
---

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 1340)May include surrounding context.

md
name: contentstudio
description: ContentStudio is a tool to schedule social-media posts, manage the social inbox, and pull performance analytics across Facebook, LinkedIn, Twitter/X, Instagram, YouTube, TikTok, Pinterest, Threads, Tumblr, Bluesky, and Google Business Profile. Use when the user wants to list/create/delete/approve posts, find the best time to post, generate or edit images with AI, read and reply to DMs, comments and reviews, manage media, audit workspaces, accounts, campaigns, labels, categories, or team-members, or pull analytics reports (top posts, engagement, impressions, follower growth, AI insights, etc.) on their ContentStudio account.
version: 1.5.0
homepage: https://api.contentstudio.io/guide
metadata: {"openclaw":{"emoji":"📅","requires":{"bins":["contentstudio"],"env":["CONTENTSTUDIO_API_KEY"]}}}
---

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 1341)May include surrounding context.

md
name: contentstudio
description: ContentStudio is a tool to schedule social-media posts, manage the social inbox, and pull performance analytics across Facebook, LinkedIn, Twitter/X, Instagram, YouTube, TikTok, Pinterest, Threads, Tumblr, Bluesky, and Google Business Profile. Use when the user wants to list/create/delete/approve posts, find the best time to post, generate or edit images with AI, read and reply to DMs, comments and reviews, manage media, audit workspaces, accounts, campaigns, labels, categories, or team-members, or pull analytics reports (top posts, engagement, impressions, follower growth, AI insights, etc.) on their ContentStudio account.
version: 1.5.0
homepage: https://api.contentstudio.io/guide
metadata: {"openclaw":{"emoji":"📅","requires":{"bins":["contentstudio"],"env":["CONTENTSTUDIO_API_KEY"]}}}
---

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 1357)May include surrounding context.

md
name: contentstudio
description: ContentStudio is a tool to schedule social-media posts, manage the social inbox, and pull performance analytics across Facebook, LinkedIn, Twitter/X, Instagram, YouTube, TikTok, Pinterest, Threads, Tumblr, Bluesky, and Google Business Profile. Use when the user wants to list/create/delete/approve posts, find the best time to post, generate or edit images with AI, read and reply to DMs, comments and reviews, manage media, audit workspaces, accounts, campaigns, labels, categories, or team-members, or pull analytics reports (top posts, engagement, impressions, follower growth, AI insights, etc.) on their ContentStudio account.
version: 1.5.0
homepage: https://api.contentstudio.io/guide
metadata: {"openclaw":{"emoji":"📅","requires":{"bins":["contentstudio"],"env":["CONTENTSTUDIO_API_KEY"]}}}
---

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 1370)May include surrounding context.

md
name: contentstudio
description: ContentStudio is a tool to schedule social-media posts, manage the social inbox, and pull performance analytics across Facebook, LinkedIn, Twitter/X, Instagram, YouTube, TikTok, Pinterest, Threads, Tumblr, Bluesky, and Google Business Profile. Use when the user wants to list/create/delete/approve posts, find the best time to post, generate or edit images with AI, read and reply to DMs, comments and reviews, manage media, audit workspaces, accounts, campaigns, labels, categories, or team-members, or pull analytics reports (top posts, engagement, impressions, follower growth, AI insights, etc.) on their ContentStudio account.
version: 1.5.0
homepage: https://api.contentstudio.io/guide
metadata: {"openclaw":{"emoji":"📅","requires":{"bins":["contentstudio"],"env":["CONTENTSTUDIO_API_KEY"]}}}
---

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 1597)May include surrounding context.

md
name: contentstudio
description: ContentStudio is a tool to schedule social-media posts, manage the social inbox, and pull performance analytics across Facebook, LinkedIn, Twitter/X, Instagram, YouTube, TikTok, Pinterest, Threads, Tumblr, Bluesky, and Google Business Profile. Use when the user wants to list/create/delete/approve posts, find the best time to post, generate or edit images with AI, read and reply to DMs, comments and reviews, manage media, audit workspaces, accounts, campaigns, labels, categories, or team-members, or pull analytics reports (top posts, engagement, impressions, follower growth, AI insights, etc.) on their ContentStudio account.
version: 1.5.0
homepage: https://api.contentstudio.io/guide
metadata: {"openclaw":{"emoji":"📅","requires":{"bins":["contentstudio"],"env":["CONTENTSTUDIO_API_KEY"]}}}
---

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 1598)May include surrounding context.

md
name: contentstudio
description: ContentStudio is a tool to schedule social-media posts, manage the social inbox, and pull performance analytics across Facebook, LinkedIn, Twitter/X, Instagram, YouTube, TikTok, Pinterest, Threads, Tumblr, Bluesky, and Google Business Profile. Use when the user wants to list/create/delete/approve posts, find the best time to post, generate or edit images with AI, read and reply to DMs, comments and reviews, manage media, audit workspaces, accounts, campaigns, labels, categories, or team-members, or pull analytics reports (top posts, engagement, impressions, follower growth, AI insights, etc.) on their ContentStudio account.
version: 1.5.0
homepage: https://api.contentstudio.io/guide
metadata: {"openclaw":{"emoji":"📅","requires":{"bins":["contentstudio"],"env":["CONTENTSTUDIO_API_KEY"]}}}
---

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 5)May include surrounding context.

md
name: contentstudio
description: ContentStudio is a tool to schedule social-media posts, manage the social inbox, and pull performance analytics across Facebook, LinkedIn, Twitter/X, Instagram, YouTube, TikTok, Pinterest, Threads, Tumblr, Bluesky, and Google Business Profile. Use when the user wants to list/create/delete/approve posts, find the best time to post, generate or edit images with AI, read and reply to DMs, comments and reviews, manage media, audit workspaces, accounts, campaigns, labels, categories, or team-members, or pull analytics reports (top posts, engagement, impressions, follower growth, AI insights, etc.) on their ContentStudio account.
version: 1.5.0
homepage: https://api.contentstudio.io/guide
metadata: {"openclaw":{"emoji":"📅","requires":{"bins":["contentstudio"],"env":["CONTENTSTUDIO_API_KEY"]}}}
---

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 19)May include surrounding context.

md
name: contentstudio
description: ContentStudio is a tool to schedule social-media posts, manage the social inbox, and pull performance analytics across Facebook, LinkedIn, Twitter/X, Instagram, YouTube, TikTok, Pinterest, Threads, Tumblr, Bluesky, and Google Business Profile. Use when the user wants to list/create/delete/approve posts, find the best time to post, generate or edit images with AI, read and reply to DMs, comments and reviews, manage media, audit workspaces, accounts, campaigns, labels, categories, or team-members, or pull analytics reports (top posts, engagement, impressions, follower growth, AI insights, etc.) on their ContentStudio account.
version: 1.5.0
homepage: https://api.contentstudio.io/guide
metadata: {"openclaw":{"emoji":"📅","requires":{"bins":["contentstudio"],"env":["CONTENTSTUDIO_API_KEY"]}}}
---

Static analysis

No suspicious patterns detected.