Back to skill

Security audit

PostNitro

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent PostNitro automation guide, with real risks around live social posting, an unpinned external CLI, and plaintext API-key storage that are mostly disclosed and purpose-aligned.

Install only if you are comfortable trusting the external @postnitro/cli package and giving it a PostNitro API key with access to your connected social accounts. Prefer an environment variable or temporary key over saved plaintext auth on shared machines, confirm target account and scheduled time before any SCHEDULED action, and use DRAFT when unsure.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:14
Finding

Unpinned and Unaudited Globally Installed CLI Dependency

Content
View full analysis
Remediation
View remediation
``` 2. Publish and verify the expected npm integrity hash or signed package provenance. 3. Provide a link to the source revision corresponding exactly to the pinned release. 4. Document a reproducible build and release-verification process. 5. Prefer a project-local installation over a global installation where practical. 6. Disable npm lifecycle scripts during installation if the package does not require them: ```bash npm install --ignore-scripts --save-exact @postnitro/cli@ ``` 7. Regularly audit the pinned package and its transitive dependencies before updating the documented version. 8. Advise users to install the package in an isolated, least-privileged environment. ]]>

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:19
Finding

API Key Exposure Through Command-Line Arguments and Plaintext Configuration Storage

Content
View full analysis
**Security:** `auth set-key` stores your API key in plaintext at `~/.postnitro-cli/config.json`. Restrict its file permissions and avoid shared or untrusted machines; run `auth clear` to remove it. This skill runs **no background processes, cron jobs, or startup scripts** — the only local state is the API key and saved defaults, both disclosed above. ``` `references/cli-reference.md`, lines 10–24: ```markdown | Flag | Purpose | |------|---------| | `--api-key ` | API key (overrides env/saved config) | | `-V, --version` | Print version | | `-h, --help` | Help for any command/subcommand | ## auth ``` postnitro auth set-key # save to ~/.postnitro-cli/config.json postnitro auth status # { configured, source, apiKey (masked) } postnitro auth clear # remove saved key ``` > **Security:** `auth set-key` stores the API key in **plaintext** at `~/.postnitro-cli/config.json`. Restrict its file permissions (`chmod 600`), avoid shared or untrusted machines, and run `auth clear` to remove it. In CI, prefer `--api-key` or the `POSTNITRO_API_KEY` env var over the saved file. ``` ### Technical Analysis The documented authentication mechanisms permit API keys to be supplied directly as command-line arguments and saved unencrypted in `~/.postnitro-cli/config.json`. Command-line secrets may be exposed through: - Shell history files. - Process listings while a command is ru ...[truncated 2663 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Session Persistence

Medium
Category
Rogue Agent
Confidence
93% confidence
Finding

The skill explicitly documents persistent credential storage via 'auth set-key', which saves the API key in plaintext under ~/.postnitro-cli/config.json. Persistent local storage of a live API credential increases exposure to credential theft on shared machines, by other local processes, or via later tooling that reads home-directory files, enabling unauthorized use of the PostNitro account and linked publishing capabilities.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: postnitro
description: Create on-brand social media carousels, single-image posts, and short videos, and schedule them to LinkedIn, Instagram, TikTok, and Threads from a single command. Turn a topic, article, or X thread into a finished multi-slide post, image, or video (with an optional audio track) — or import your own content — then publish or draft it automatically. Fully scriptable (JSON in, JSON out), so an AI agent can run the entire create-to-schedule workflow. Use this skill whenever the user wants to create a carousel, image post, video, reel, slide post, or multi-slide content, repurpose an article, blog post, or X thread into slides or a video, or automate and schedule social media posts. Use it to create and schedule content through PostNitro, not as a general social-media strategy advisor. Requires a PostNitro API key.
homepage: https://postnitro.ai
metadata: {"openclaw":{"emoji":"🎠","primaryEnv":"POSTNITRO_API_KEY","requires":{"bins":[],"env":["POSTNITRO_API_KEY"]}}}
---

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The description uses broad trigger language ('Use this skill whenever...') that can cause an agent to invoke the skill in situations where the user did not clearly intend content creation or scheduling. Because this skill can publish or draft posts to live social accounts, over-invocation raises the risk of unintended external actions, unnecessary API usage, and accidental posting to connected platforms.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-reference.md (reported line 24)May include surrounding context.

postnitro auth clear # remove saved key

text

> **Security:** `auth set-key` stores the API key in **plaintext** at `~/.postnitro-cli/config.json`. Restrict its file permissions (`chmod 600`), avoid shared or untrusted machines, and run `auth clear` to remove it. In CI, prefer `--api-key` or the `POSTNITRO_API_KEY` env var over the saved file.

## defaults

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The examples include ready-to-run scheduling commands that target real linked social accounts and future publish times, but they do not prominently warn that executing them can create live scheduled posts. In an agentic context, this increases the chance of unintended publication because an automated system may treat the examples as safe defaults and schedule content without explicit user confirmation.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This JSON file contains slide content but does not specify any invocation conditions, trigger phrases, or exclusion criteria for when the associated skill should activate. For manifest files, the absence of trigger specificity can lead to ambiguous activation behavior if this file is used as part of skill configuration.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.