Back to skill

Security audit

B2c Organic Social Media Marketing

Security checks for vulnerabilities and agentic risk

Overview

This marketing skill is mostly a coaching guide, but it has review-worthy ambiguity around posting authority, unpinned companion installs, and persistent tracking of business metrics.

Install only if you want an agent to advise on organic social growth and you are comfortable reviewing any posting actions yourself. Do not run the companion install commands unless you trust the publishers, have checked the exact versions, and can limit any social-account credentials or API tokens. Treat the performance log as persistent business data and avoid storing sensitive attribution details unless you intentionally want that retained.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:205
Finding

Unpinned Third-Party Skill Installation Creates Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 205–221
Vulnerability Type: Unpinned third-party dependencies from external sources
Risk Level: Medium

The vulnerable instructions are:

markdown
Once formats are proven and accounts established, use [Post Bridge](https://www.post-bridge.com) to upload once and post everywhere, schedule a week in one sitting, and manage multiple accounts without logging in and out.

For the posting mechanics, install the companion skill:

npx skills add post-bridge-hq/agent-mode --skill post-bridge

text

That skill wraps the Post Bridge API and `postbridge-cli` for media upload, scheduling, per-platform config and result tracking.

Once you are past roughly 15 accounts the problem changes from growth to
operations: keeping accounts un-restricted, reading per-account results, and
knowing when a failure is worth fixing versus waiting out. That is a different
skill:

openclaw skills install @jackfriks/multi-account-operator

text

Technical Analysis

The Skill recommends installing two externally maintained components without specifying immutable versions, commit hashes, checksums, or integrity metadata. The commands therefore resolve mutable third-party content at installation time. The downloaded components are not included in this repository and could not be reviewed as part of this audit.

This violates dependency integrity and reproducibility principles. Even if the current upstream packages are benign, a compromised maintainer account, transferred namespace, malicious update, or upstream repository compromise could cause the same documented commands to install different and potentially hostile content later.

Because the companion components are intended to perform media uploads, scheduling, platform configuration, and multi-account management, they may receive API credentials or authenticated access to social-media accounts. Their effective per ...[truncated 1697 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin each external dependency to an immutable, reviewed version or commit hash rather than a mutable package identifier.
  • Publish and verify cryptographic checksums, signatures, or package-manager integrity metadata before installation.
  • Confirm publisher identity and ownership of each namespace and document the authoritative source repository.
  • Review the exact pinned source and its transitive dependencies before recommending installation.
  • Document the permissions, credentials, filesystem paths, and network destinations required by each companion component.
  • Apply least privilege by using scoped API tokens and restricting filesystem and network access.
  • Require explicit user approval after presenting the dependency source, pinned version, integrity value, and requested capabilities.
  • Establish a controlled update process in which newer revisions are reviewed and repinned rather than automatically resolved.
  • Prefer sandboxed execution and revoke or rotate credentials if dependency integrity cannot be established.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file claims the skill is advisory only and does not schedule jobs or perform posting actions, but later operational instructions tell the agent to post content and maintain logs. This kind of capability mismatch is dangerous because users and orchestrators may grant trust based on the safer description while the body of the skill pushes toward state-changing behavior.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The role section says 'When they have content ready, post it,' which conflicts with the earlier statement that posting is delegated to a separate companion skill and must be opted into. That contradiction can cause an agent to overstep intended permissions or activate posting-related behaviors without the explicit installation and consent boundaries the intro claims exist.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

The skill instructs users to run an unpinned npx skills add ... command, which can fetch and execute whatever package version is current at install time. That creates a supply-chain risk: a compromised or unexpected upstream release could execute code in the user's environment, and the skill provides no version pinning, integrity check, or trust boundary warning.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The instruction to keep a persistent log of post performance and download attribution data in workspace memory creates durable storage of potentially sensitive business information. Persistent memory increases exposure to cross-task leakage, unauthorized reuse, or accidental disclosure, and the skill does not specify minimization, retention limits, access controls, or user approval.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file includes an invocation-style condition that activates coaching behavior when the user 'asks for help or seems stuck.' Those phrases are extremely broad and overlap with common everyday interaction, and the file does not provide exclusion conditions or tighter trigger constraints.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The skill directs the agent to write performance and attribution data into workspace/memory/b2c-social-log.md without warning the user that persistent storage will occur. Silent persistence of user-provided business metrics can create privacy, retention, and consent issues, especially if the workspace is shared, synced, or later reused in unrelated sessions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.