Back to skill

Security audit

Social Media Manager

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed social media content helper with template-generation scripts and no evidence of hidden access, persistence, credential use, network calls, or automatic posting.

Before installing, treat this as a local content-assistance skill, not a social account automation tool. Use only analytics, competitor information, and audience data you are authorized to process, avoid putting identifiable audience records into config files, and be aware that --output options can overwrite files at paths you provide.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (7)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
70% confidence
Finding

Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.

Content

Scanner excerpt · SKILL.md (reported line 375)May include surrounding context.

md
## Notes

- Always comply with platform terms of service
- Maintain consistent brand identity
- Engage with comments and messages promptly
- Track competitors and industry trends

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The configuration explicitly requests audience demographics and location-related data without any minimization, consent, retention, or handling guidance. That can encourage collection of personal or quasi-personal data in an uncontrolled way, increasing privacy, compliance, and misuse risk if users include identifiable audience information.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The post templates and generated strings are written entirely in English, and the script provides no option for users to select another language or opt into English-only output. Under the stated policy, forcing a specific language without user choice is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This markdown file says the skill can analyze post performance metrics and benchmark against competitors, which may involve handling account analytics or third-party social data. The description does not include any user-facing warning about reviewing connected-account data, respecting privacy, or ensuring authorization before analyzing such information.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The phrase "Create专属 hashtags" mixes English with Chinese in the guidance, introducing a language-specific element without offering a user choice or explaining why this locale is required. This can conflict with language/locale consistency expectations for a general best-practices document.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This code writes JSON output to an arbitrary path supplied by the user, but the only disclosure is the argument name itself. There is no prior warning, confirmation, or explanatory comment/docstring that the tool will create or overwrite a file when --output is used.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code writes generated content to a user-specified path when --output is provided, but it does not warn that an existing file may be overwritten. Although it prints a success message after writing, there is no prior disclosure or confirmation about the file modification itself.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.