Postproxy

PassAudited by VirusTotal on May 12, 2026.

Findings (1)

The skill is classified as suspicious due to the presence of high-risk capabilities, specifically `allowed-tools: Bash` and the ability to upload local files (`-F "media[]=@/path/to/image.jpg"`) to an external API (api.postproxy.dev) as demonstrated in SKILL.md. While these capabilities are plausibly needed for the stated purpose of managing social media posts with media, they grant broad shell access and file read/exfiltration potential to a third-party service, which constitutes a significant risk without clear malicious intent from the skill developer.