Back to skill

Security audit

Crebee Agent Skill V1.9.9

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent social-media gateway, but it gives an agent broad posting, cancellation, local media upload, and audience-analytics access without clear confirmation or privacy guardrails.

Review this before installing if you manage real social accounts. Only use it with accounts you are authorized to operate, confirm every publish/cancel action yourself, verify local media paths before upload, and treat bearer tokens, account IDs, revenue data, and audience/fan analytics as sensitive.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (24)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill enables sensitive operations across logged-in social-media accounts, including content publishing, analytics access, and audience-profile retrieval, but does not require explicit user confirmation, privacy warnings, or safeguards for irreversible actions. In an agent context, this increases the risk of unintended posting, over-collection of account data, or disclosure of follower/engagement insights from locally authenticated accounts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
79% confidence
Finding

The natural-language description presents the skill entirely in Chinese and scopes it to managing Chinese social-media platforms, but it does not state that Chinese is merely the documentation language or offer the user a language choice. Under the policy, forcing a specific language or locale without opt-in is a violation unless the constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation enables account-scoped publishing, fan-data access, comments, notices, and analytics retrieval without any visible guidance on consent, privacy sensitivity, or action impact. In an agent setting, this increases the risk of silent high-impact operations or unnecessary collection of account and audience data without adequate user awareness.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The manifest describes account management, content publishing, analytics, audience insights, and topic/music/activity search for social media operations. This file additionally documents access to B站收益中心 endpoints that expose monetization activity and income overview/trend data, which is a business-financial capability not clearly covered by the stated purpose of social-media运营 management.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file documents an endpoint that returns detailed fan portrait data including age, gender, city, device brand, interests, and activity, but it does not include any warning about the sensitivity of this audience data or privacy implications. For markdown files, safety-affecting behaviors involving user data should be accompanied by a disclosure so operators understand the privacy impact.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The publishing parameter documentation references local file paths for videos, covers, and images, but does not explicitly state that the referenced local media and associated post metadata will be uploaded to Kuaishou when used. In an agent skill, this can cause unintended exfiltration of local files or sensitive embedded metadata if operators or downstream agents assume the paths are only local references or staging artifacts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file documents analytics and audience-profile endpoints that expose account-level performance and follower demographic data, but it does not clearly warn that these APIs access potentially sensitive business intelligence and personal-data-adjacent information. In an agentic automation context, that omission increases the risk of overbroad or silent collection because callers may treat these endpoints as routine metadata access rather than sensitive analytics retrieval.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file documents publish parameters including local videoPath, coverPath, images, mentions, location, links, and scheduling fields, but it does not warn users that these inputs can result in media and associated metadata being sent to external platform APIs. For a markdown skill description, this is a missing disclosure about behavior that can affect user data and privacy.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file documents required request headers and accountArgs, then goes on to expose analytics and user portrait endpoints such as getDataOverview and getFansPortrait. Because the skill description omits any user-facing warning that using these endpoints sends account identifiers and potentially sensitive audience/profile data to backend services, it lacks disclosure for privacy-impacting behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file documents API calls that send accountArgs.accountID and retrieve user analytics, audience source, and profile data, but it does not include any user-facing warning about privacy or data handling. Under the markdown-file criteria for SQP-2, descriptions should warn when behavior can affect user data or privacy.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The publish parameter docs instruct callers to provide local file paths for videos, covers, and images without clearly warning that these paths will cause local files to be read and uploaded to a remote service. In an agent setting, this can blur the trust boundary and lead to unintended exfiltration of sensitive local files if a user or upstream prompt supplies unexpected paths.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file describes network requests that require an Authorization bearer token and an accountArgs object containing platform and account identifiers. Under the markdown-specific SQP-2 criteria, it lacks any warning that using these endpoints sends authenticated account data to external/backend services, which may affect privacy or account integrity.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The manifest frames this skill as an automation gateway for managing social-media accounts, publishing content, obtaining analytics, audience insights, and searching topics/events/music across platforms. In this Zhihu file, the documented capabilities expand into creator-discovery and engagement workflows such as blogger rankings, excellent answerer rankings, invite-to-answer timelines, and recommended questions, which are not clearly covered by the stated purpose and go beyond straightforward account/content management.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation exposes powerful batch publishing and task-cancellation capabilities across multiple external social media platforms without clearly warning about downstream effects such as unauthorized posting, mass content propagation, account misuse, or accidental disruption. In an agent skill context, omission of these guardrails increases the chance that an agent or integrator will treat the API as low-risk automation and perform high-impact actions without user confirmation or scope checks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file instructs callers to provide local absolute file paths and elsewhere documents Bearer-token use for WebSocket, SSE, and API calls, but it does not warn that these values are sensitive and may expose workstation layouts, usernames, local file contents, or reusable credentials if logged or echoed. In an agent-driven environment, these fields are especially risky because agents commonly serialize requests, traces, and errors into logs or third-party observability systems.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This markdown file documents required authenticated requests using an Authorization bearer token and accountArgs containing account identifiers. Under the markdown-specific warning rule, it lacks an explicit warning that these requests involve sensitive account data and should be handled carefully.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

Several endpoints define the sLocale language parameter with a default of zh_CN, but the document does not indicate that users can choose another locale or that the Chinese-only default is a required regional constraint. This is a natural-language locale policy issue because it implicitly forces a specific language setting without user opt-in.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The manifest focuses on publishing, account info, analytics, audience profiles, and search across social platforms. The documented getNotices capability retrieves creator-center notifications such as incentive reports, classes, solicitation activities, and violation announcements, which is an operational inbox/compliance-monitoring function not mentioned in the declared skill description.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file describes API requests that require an Authorization bearer token and accountArgs containing account identifiers, but it does not include any warning about the sensitivity of these values or the privacy implications of transmitting them. Under the markdown-specific warning criterion, documentation that can affect privacy or account integrity should disclose the sensitive nature of credentials and account-scoped data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown file describes network requests that include an Authorization bearer token and accountArgs containing platform/account identifiers, which can affect user privacy and account integrity. The documentation presents these calls as required inputs but does not include any warning or disclosure that invoking the skill will send authenticated account data to platform APIs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The natural-language parameter description states that the language defaults to zh, which imposes a specific locale behavior without documenting user opt-in or explaining why only that locale should be used. Under the policy, forcing a language or locale without choice or justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This markdown file documents required headers and request bodies for API calls, including a Bearer token and accountArgs containing account identifiers. Under SQP-2 for markdown files, user-facing documentation should warn when behavior may affect privacy or transmit account-related data, but no such warning is present here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file describes requests that require an Authorization bearer token and accountArgs containing platform/account identifiers, which can affect privacy and account integrity if sent to the wrong environment or mishandled. The document gives operational details but provides no user-facing warning about handling these sensitive values securely.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file forces a single language/locale experience through its natural-language documentation, and there is no opt-in, alternative language, or explanation that the skill is intentionally region-specific. The policy requires avoiding language or locale constraints unless the user is given a choice or the restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.