Back to skill

Security audit

Content Workflow Engine

Security checks for vulnerabilities and agentic risk

Overview

This skill is an overbroad content-automation prototype with unsafe command execution and weak controls around credentials, posting workflows, and local files.

Review this skill before installing. Treat it as a prototype, not a production content automation system. Do not connect real publishing, social, email, analytics, or storage credentials until shell execution and path handling are fixed, secrets are stored safely, live posting requires explicit confirmation, and report/log redaction is added.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (6)

T09 · Insecure Skill Coding Practices

Error
Location
index.js:31
Finding

OS Command Injection Through Node.js CLI Arguments

Content
View full analysis
{ const scriptPath = path.join(__dirname, 'scripts', scriptName); if (!fs.existsSync(scriptPath)) { reject(new Error(`Script not found: ${scriptPath}`)); return; } const cmd = `python3 "${scriptPath}" ${args.join(' ')}`; console.log(`🚀 Running: ${cmd}`); exec(cmd, (error, stdout, stderr) => { ``` ### Technical Analysis The wrapper constructs a command string by concatenating command-line arguments with `args.join(' ')` and passes the result to `child_process.exec()`. Because `exec()` invokes a system shell, shell metacharacters in an argument are interpreted as command syntax rather than as literal Python arguments. The script path is quoted, but the attacker-controlled arguments are not escaped or quoted. Validation by the Python scripts occurs only after the shell has already interpreted the command. ### Attack Path 1. An attacker invokes one of the supported wrapper commands. 2. The attacker places a shell operator and an additional command inside an option value. 3. `process.argv.slice(2)` preserves the malicious input. 4. `args.join(' ')` inserts it directly into `cmd`. 5. `exec()` passes the constructed string to the system shell. 6. The injected command executes with the privileges of the Node.js process. For example, a malicious argument containing a command separator could cause the shell to run an additional local command before or after the intended Python script. ### Impact Assessment Successful exploitation provides arbitrary command execution under the account running the Skill. The attacker can read or modify files accessible to that account, execute installed programs, access environment variables, and potentially use ...[truncated 140 chars]
Remediation
View remediation
{ if (error) { reject(new Error(`Script failed: ${error.message}`)); return; } resolve(stdout); } ); ``` ]]>

T09 · Insecure Skill Coding Practices

Error
Location
scripts/run_workflow.py:129
Finding

Path Traversal Enables Execution of Local Python Modules

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/create_workflow.py:79
Finding

Workflow Name Path Traversal Allows JSON File Overwrite

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/brainstorm.py:168
Finding

Brainstorm Output Filename Path Traversal

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/run_workflow.py:340
Finding

Workflow-Controlled Report ID Allows Output Path Traversal

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/workflow_templates/blog_automated.py:288
Finding

Predictable Test File Is Overwritten and Deleted

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (21)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description promises broad workflow automation for content creation, management, distribution, publishing integrations, and analytics. The actual code only performs content ideation: it generates topic-based idea titles using predefined templates and random fillers, adds simple metadata, prints results, and optionally saves them locally. It does not connect to external services, schedule posts, manage calendars, orchestrate workflows, publish content, or analyze performance. While brainstorming content ideas is loosely related to content creation, the primary purpose is materially narrower than the declared end-to-end automation platform, so this is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
91% confidence
Finding

The skill instructs users to store sensitive API credentials in environment variables or config files and shows a .env example with high-value tokens and app passwords. Without explicit secret-handling guidance, users may place credentials in plaintext files that are accidentally committed, exposed in logs, or read by other processes and tools in the agent environment.

Content

Scanner excerpt · SKILL.md (reported line 233)May include surrounding context.

Store API credentials in environment variables or config file:

bash
# Example .env file
WORDPRESS_URL=https://yourblog.com/wp-json
WORDPRESS_USER=your_username
WORDPRESS_APP_PASSWORD=your_app_password

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The listing promotes direct publishing, scheduling, and newsletter automation across external platforms but does not clearly warn users that the skill may post, send, or modify content on their behalf. In a workflow automation skill, this omission increases the chance of unintended external actions, accidental spam, or unauthorized changes if users enable integrations without understanding the operational scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file instructs users to copy a config file and add API keys while advertising broad integrations with AI, publishing, social, email, analytics, and storage services, yet it provides no clear warning about credential sensitivity or that content and metadata will be transmitted to external providers. This can lead users to mishandle secrets, overprovision access, or unknowingly expose proprietary or personal data to third-party APIs.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill advertises and demonstrates shell execution plus file read/write behavior through numerous python3 scripts/... commands, but it declares no permissions or allowed-tools scope. In an agent environment, this widens the effective authority of the skill and makes it easier for the skill to be invoked with more filesystem or shell access than users expect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly describes publishing to WordPress, scheduling social posts, and sending newsletters, but it does not prominently warn that these actions may cause real external transmission or live posting. In agent-driven workflows, users may trigger irreversible public actions or outbound messaging without understanding that the examples can affect production platforms.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The wrapper builds a shell command string with args.join(' ') and passes it to child_process.exec, which invokes a shell. Because command-line arguments are user-controlled and not escaped or validated, an attacker can inject shell metacharacters and execute arbitrary OS commands, not just the intended Python script. In a content-workflow skill, this is especially dangerous because inputs may come from automation pipelines or external systems, increasing exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The code executes shell commands derived from user-supplied arguments with only a generic Running: log and no meaningful warning, confirmation, or trust boundary enforcement. This compounds the command-injection risk by making dangerous execution implicit in normal workflow use, so users or upstream automation may unknowingly pass hostile input directly into a shell.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide describes fully automated publishing to WordPress and automated distribution to social media, newsletters, RSS, and community sites without an explicit warning that these actions can post externally, create public-facing content, and trigger irreversible or reputationally sensitive actions. In an agent skill context, this increases the risk that a user or downstream agent enables the workflow without understanding that generated content may be automatically published or shared across multiple platforms.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The guide repeatedly describes automated scheduling and API-based posting to external social platforms, including concrete posting scripts, without a prominent warning that these actions can trigger real live publication. In an agent skill context, that omission can cause unintended posts, reputational harm, or misuse of connected accounts if a user or downstream agent assumes the examples are safe to run in a dry-run manner.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The workflow documents engagement monitoring, sentiment analysis, link tracking, alerting, and analytics collection, but does not clearly warn users that these behaviors may collect, process, and store personal or behavioral data from social platforms. In a content automation skill, this increases the risk of privacy noncompliance, overcollection, and operator misuse because users may enable tracking without understanding consent, retention, or jurisdictional obligations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The runner dynamically imports and executes a Python module based on the workflow's tool name, with no allowlist or trust boundary enforcement beyond file existence under the local tools directory. If an attacker can place or modify files in that directory, or can influence workflow definitions in a shared environment, this becomes arbitrary code execution inside the workflow process.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script prints the entire input payload to stdout without redaction. Workflow input can reasonably contain sensitive prompts, credentials, draft content, recipient data, or integration parameters, which may then leak into terminal scrollback, CI logs, orchestration logs, or support artifacts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Execution reports persist full inputs and stage outputs to disk with no explicit user consent or retention controls. Because this skill orchestrates multi-stage content and publishing workflows, the stored artifacts can aggregate sensitive business content, credentials, URLs, and operational metadata into one easily discoverable file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The schedule generator forces a specific locale/timezone in every returned schedule object. This is a natural-language locale policy concern because users are not offered any timezone selection or opt-in, and the template is not documented as being region-specific.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill manifest supports creating and automating content workflows, and this file mostly builds a workflow JSON template. However, the test path goes beyond template creation by invoking a separate runner via subprocess, causing actual workflow execution behavior that is not clearly justified by a template-generation script's documented purpose.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/workflow_templates/blog_automated.py (reported line 298)May include surrounding context.

python
json.dump(test_input, f, indent=2)
        
        # Run workflow
        result = subprocess.run([
            "python3", "run_workflow.py",
            "--workflow", str(workflow_file),
            "--input-file", "test_input.json",

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This JSON manifest describes an "Automated blog post creation and publishing" pipeline but does not specify any activation constraints, scope limits, or exclusion conditions. For a manifest file, that lack of specificity makes the trigger/usage context ambiguous and could lead to unintended invocation in broader content-generation contexts.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The --use-ai flag help text says 'Use AI for idea generation (requires API key)', and the module docstring also says ideas are generated 'using AI or templates'. In practice, generate_ideas ignores the use_ai parameter entirely and always produces ideas from local random templates, so the documentation and user-facing interface actively misstate the behavior.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The report includes full input_data, stage_results, and tracebacks and writes them to disk automatically in a predictable local directory. In content workflows, inputs and outputs may contain API tokens, unpublished content, customer data, or other sensitive material, so this creates a local data exposure and retention risk if the host is multi-user, backed up broadly, or logs are later shared.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The docstring for test_workflow implies a self-contained validation of the workflow definition. In practice, the function writes a temporary input file and invokes run_workflow.py through subprocess, which is materially different from an internal test and introduces external execution side effects.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.dynamic_code_execution, suspicious.exposed_secret_literal

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
index.js:18

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/run_workflow.py:138

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
references/social_multi.md:304