Back to skill

Security audit

social-auto-tool-builder-1.1.0

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed workflow for building local social-media auto-reply tools, with dry-run and confirmation steps, but users should be careful because it can automate real posts from logged-in accounts.

Install only if you intend to build automation for accounts and repositories you control. Keep dry-run as the default, review generated replies before enabling real sends, verify platform rules, and inspect any generated code for saved browser profiles, tokens, or secrets before committing, pushing, or packaging it.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly guides users to build tooling that can perform real social-media replies, package it as an executable, and push code to Git, but it does not include a clear safety warning, authorization requirement, or misuse boundary. In this context, omission matters because the skill operationalizes automated actions against third-party platforms and can normalize deployment without reminding users to verify consent, platform policy compliance, and repository hygiene.

Content

No source excerpt is available for this finding.

Internal Network Request

Medium
Category
Server-Side Request Forgery
Confidence
70% confidence
Finding

Code issues a request to a loopback, link-local, or private-range host. This can reach internal services not meant to be exposed and is a common SSRF pivot.

Content

Scanner excerpt · SKILL.md (reported line 137)May include surrounding context.

md
python -m playwright install chromium

# 本地模型检查
python -c "import requests;print(requests.get('http://127.0.0.1:11434/api/tags',timeout=5).status_code)"

# 单轮 dry-run
python auto_responder_production.py --platform xiaohongshu --once --recent-hours 1 --max-replies 3

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The title, description, and example content are written in Chinese, which effectively fixes the skill's user-facing language without any opt-in or alternative locale. Under the policy, forcing a specific language is a natural-language policy violation unless the locale constraint is explicitly justified or optional.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.