Back to skill

Security audit

Crypto Content Automation

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a crypto content-planning helper, but it loads unreviewed code from a hard-coded local workspace path and overstates publishing support involving session cookies.

Review this skill carefully before installing. Do not provide social-platform cookies unless you are comfortable treating them as account credentials, and do not run scripts/run.py unless the external workspace import path is removed or you have verified the module it will load. The package should be corrected to include its scanner modules locally and clearly separate planned publishing from implemented scan/planning features.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T07 · Tool Hijacking and Spoofing

Error
Location
scripts/run.py:12
Finding

Untrusted External Module Execution via Hard-Coded Import Path

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

The documented purpose overstates the level of automation and external platform integration compared with what is actually described in the skill file. In a crypto-content context, overstated capabilities increase the chance that users will trust the skill with credentials or rely on it for actions affecting public accounts without adequate transparency.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The documented purpose overstates the level of automation and external platform integration compared with what is actually described in the skill file. In a crypto-content context, overstated capabilities increase the chance that users will trust the skill with credentials or rely on it for actions affecting public accounts without adequate transparency.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README presents the skill description entirely in Chinese and does not indicate that users may choose another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
79% confidence
Finding

The skill advertises scripts that read and write local files but does not declare any explicit tool scope or permissions boundary. This can lead to overbroad execution in agent environments, where the skill may gain filesystem access beyond what users reasonably expect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill promotes one-click publishing to external social platforms without clearly warning that posts may affect real user accounts. In an agent setting, omission of this warning can cause accidental or unauthorized publication, reputational harm, and loss of account control expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs users to configure platform cookies for publishing but does not warn that cookies are sensitive session credentials that can enable account takeover if exposed. Because the target platforms are real external services, mishandling these cookies could let an attacker post, impersonate the user, or access account data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file’s natural-language description and user-facing help are written in Chinese, indicating the skill is designed to operate in a specific language. Under the policy, language constraints should either be optional for the user or clearly documented as justified; this file provides neither.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The command help shown to users is exclusively in Chinese, which constitutes a language/locale restriction in natural-language content. The file does not offer an alternative language, prompt for preference, or explain a region-specific reason for this limitation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This Python file contains user-facing docstrings and CLI output entirely in Chinese, including the title, status messages, and command help text. Because the skill does not offer language selection or explain that it is intentionally region-specific, it creates a natural-language locale policy issue for users who may expect language neutrality or opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description is entirely in Chinese and presents the skill as a Chinese-language social media automation workflow, with no indication that users can choose another language or locale. This creates a natural-language policy concern because it implicitly fixes the skill to a specific language context without documented opt-in or region-specific justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

This markdown file documents that running the skill produces report and planning files in the logs directory, but it does not explicitly warn the user that executing the workflow will create or overwrite local files. For markdown files, user-facing descriptions should disclose behaviors that affect user data or the local system, even when the effect is modest.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The skill description uses Chinese-language instructions and does not indicate that users may choose another language or that the skill is intentionally limited to a Chinese-speaking audience. This can violate language/locale policy when a specific language is imposed without opt-in or justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.