Back to skill

Security audit

social

Security checks for vulnerabilities and agentic risk

Overview

This social-media helper is mostly coherent, but its listening workflow includes unsafe shell recipes and logged-in browser use that deserve review before installation.

Review the listening workflow before installing. Use it for drafting and triage, but avoid direct text substitution into shell commands, URL-encode keywords, treat fetched posts as untrusted content, and keep manual approval before any social posting.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
references/listening.md:127
Finding

Shell Command Injection Through Unsafe Keyword Substitution

Content
View full analysis
${SINCE}" \ | jq '.hits[] | {title, url, author, points, num_comments, created_at, story_id: .objectID, hn_url: ("https://news.ycombinator.com/item?id="+.objectID)}' ``` ```bash curl -s "https://hn.algolia.com/api/v1/search_by_date?query=KEYWORD&tags=comment&numericFilters=created_at_i>${SINCE}" \ | jq '.hits[] | {author, comment_text, story_title, hn_url: ("https://news.ycombinator.com/item?id="+.objectID)}' ``` It is also used for Bluesky: ```bash curl -s "https://public.api.bsky.app/xrpc/app.bsky.feed.searchPosts?q=KEYWORD&limit=25&sort=latest" \ | jq '.posts[] | {author: .author.handle, text: .record.text, likes: .likeCount, replies: .replyCount, url: ("https://bsky.app/profile/"+.author.handle+"/post/"+(.uri | split("/") | last))}' ``` ### Technical Analysis The workflow directs the Agent to replace the literal `KEYWORD` placeholder with user-controlled values such as brand names, competitor names, and search phrases. These values are placed directly inside double-quoted shell arguments without validation or shell-safe parameter handling. Double quotes do not suppress command su ...[truncated 2050 chars]
Remediation
View remediation

T01 · Skill Instruction Hijacking

Warning
Location
references/listening.md:106
Finding

Prompt Injection Exposure Through Untrusted Social and Browser Content

Content
View full analysis
${SINCE}" \ | jq '.hits[] | {author, comment_text, story_title, hn_url: ("https://news.ycombinator.com/item?id="+.objectID)}' ``` ```bash curl -s "https://public.api.bsky.app/xrpc/app.bsky.feed.searchPosts?q=KEYWORD&limit=25&sort=latest" \ | jq '.posts[] | {author: .author.handle, text: .record.text, likes: .likeCount, replies: .replyCount, url: ("https://bsky.app/profile/"+.author.handle+"/post/"+(.uri | split("/") | last))}' ``` Authenticated browser content is handled similarly: ```text **dev-browser workflow (preferred — already wired up):** 1. User logs into LinkedIn / X once in the dev-browser session 2. Claude navigates to a target URL (feed, profile, saved search, hashtag) 3. Claude reads the accessibility tree / page text, extracts posts 4. Claude scores using the rubric and drafts comments 5. User reviews and posts manually (don't auto-post — high-stakes, bot detection risk) ``` ### Technical Analysis Reddit posts, Hacker News comments, Bluesky posts, RSS entries, and LinkedIn or X page text are controlled by remote users. The Skill directs the Agent to in ...[truncated 2859 chars]
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill description contains a very large set of broad trigger phrases such as 'social media,' 'engagement,' 'what should I post,' and 'video script,' which can cause the router to invoke this skill for loosely related or ordinary requests. Over-broad activation increases the chance of incorrect skill selection, unintended file reads such as product-marketing context, and disclosure or misuse of workspace context in conversations that did not require this specialized skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JSON eval file is a manifest-like file, so vague-trigger review applies. The expected behavior explicitly says the skill 'Should trigger on casual phrasing,' which is an ambiguous activation condition and suggests broad matching that could overlap with everyday requests, without any narrowing scope or negative examples.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.