Back to plugin

Security audit

SimplePost

Security checks for vulnerabilities and agentic risk

Overview

This skill transparently connects to SimplePost to publish and manage social posts; the main risk is accidental public posting or public media if used with broad instructions.

Install this only if you want an agent to publish, schedule, draft, or manage social posts through SimplePost. Before asking it to publish, verify the exact accounts, content, media, schedule, and privacy settings, especially for TikTok and any uploaded media URLs. Keep API keys and platform credentials server-side or in approved secret storage, and use drafts or previews when intent is uncertain.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skills/simplepost/references/scheduler.md (reported line 20)May include surrounding context.

bash
yarn install
cp scheduler/.env.example scheduler/.env
yarn workspace @simple-post/scheduler db:migrate
yarn workspace @simple-post/scheduler dev

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The default prompt is a broad action trigger that directly frames the skill as ready to publish content to connected social accounts. Because publishing is an external side-effect with reputational and operational consequences, a generic invocation phrase increases the chance of accidental or insufficiently reviewed posting, especially when paired with implicit invocation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation states that returned media URLs must be publicly reachable by social platforms, but it does not clearly warn users that uploaded media may become internet-accessible. In a posting/integration skill, this can cause accidental disclosure of private or internal media if operators assume uploads remain private.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The workflow explicitly instructs the assistant to call mutating tools such as create_post, update_scheduled_post, and discard_scheduled_post, including immediate publishing with postingMode: "now", without requiring an explicit confirmation step or user warning before external state is changed. In an AI-agent setting, this increases the chance of unintended publication, edits, or deletion of social content from ambiguous prompts or model misinterpretation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The TikTok section documents a server-side default of PUBLIC_TO_EVERYONE when privacy is omitted, but it does not require the agent to surface this consequence prominently before creating, scheduling, or publishing a TikTok post. Because audience visibility is privacy-sensitive and social posting is externally visible, an omitted setting could cause users to publish more broadly than intended.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation explicitly advertises 'S3-compatible media upload with public URLs' but does not warn that uploaded media will be publicly accessible and potentially indexable or shareable beyond the intended audience. In a social-posting product, users may upload embargoed, private, or sensitive assets, so omission of the privacy implications can lead to inadvertent disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file documents posting content and media to third-party platforms such as X, Telegram, LinkedIn, YouTube, and Facebook, which is a privacy- and integrity-relevant action. The description does not include any warning that content, media, or credentials may be sent to external services, nor any caution to obtain user confirmation before publishing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This markdown file applies to SQP-2, and it instructs users to send an x-api-key header while later noting that users manage platform credentials themselves. The document does not include any warning that these values are sensitive secrets or caution against exposing them in client-side or untrusted contexts.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
skills/simplepost/references/http-server.md:16
Evidence
x-api-key: [REDACTED]