Back to skill

Security audit

Social Media Manager

Security checks for vulnerabilities and agentic risk

Overview

This social media helper is a disclosed content, hashtag, and calendar generator with no evidence of hidden access, persistence, or credential use.

Install only if you want local assistance drafting social media content and planning schedules. Review generated posts before publishing, and be careful with --output paths because generated JSON files may overwrite an existing destination.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
70% confidence
Finding

Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.

Content

Scanner excerpt · SKILL.md (reported line 375)May include surrounding context.

md
## Notes

- Always comply with platform terms of service
- Maintain consistent brand identity
- Engage with comments and messages promptly
- Track competitors and industry trends

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document is otherwise written in English, but line L095 includes Chinese text ("专属") inline without offering a language choice or explaining a locale-specific purpose. This creates a natural-language locale inconsistency that may violate organizational language policy for skills expected to operate in a single language unless users opt in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This code writes generated content to a user-specified file path, but there is no warning, confirmation, or comment indicating that an existing file may be overwritten. Although the operation is not highly sensitive, SQP-2 applies to file writes in code when there is no disclosure at all.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.