Back to skill

Security audit

Post Bridge

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly clear about managing real social media accounts, but it authorizes an unpinned npm CLI to handle live posting credentials and account actions.

Review this skill before installing if it will touch production social accounts. Prefer the bundled `artifact/scripts/post-bridge.js` or a pinned, audited CLI version, avoid putting live API keys directly in shell commands, use narrowly scoped or rotated Post Bridge API keys, and keep draft/confirmation workflows enabled for publishing actions.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:30
Finding

Execution of an Unpinned npm Package

Content
View full analysis
` (no install needed; npx fetches it on first use). Requires Node.js 18+. If `npx postbridge-cli` is unavailable for any reason, fall back to the bundled script at `/scripts/post-bridge.js` (same commands and flags). ``` ### Technical Analysis The Skill directs the Agent to run `npx postbridge-cli` without specifying an exact package version or verifying package integrity. When the package is absent from the local cache, `npx` retrieves the registry-selected release and executes its installation and runtime code. This creates a mutable supply-chain execution path: the code actually executed can change after the Skill has been audited. The bundled `scripts/post-bridge.js` implementation is available and auditable, but the documentation treats remote npm execution as the preferred path and the bundled script only as a fallback. A compromised npm publisher account, malicious future package release, registry compromise, or dependency-chain compromise could therefore introduce arbitrary code without any modification to this repository. ### Attack Path 1. An attacker compromises the npm account, release process, or dependency chain associated with `postbridge-cli`. 2. The attacker publishes a malicious version under the legitimate package name. 3. A user or Agent follows `SKILL.md` and invokes `npx postbridge-cli`. 4. `npx` resolves and downloads the malicious release because no exact version or integrity value is required. 5. The package executes with the privileges of the invoking user or Agent. 6. The malicious code ...[truncated 830 chars]
Remediation
View remediation
``` 2. If npm execution is required, pin an exact audited version rather than allowing registry resolution of the latest release: ```bash npx --yes postbridge-cli@ ``` 3. Verify package provenance and integrity before execution. Maintain an approved version and expected package hash in the Skill documentation or installation process. 4. Use a lockfile and a controlled installation step instead of downloading executable code during each task. 5. Review new releases before updating the pinned version. 6. Run the CLI with only the environment variables and filesystem access needed for the requested operation. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:60
Finding

Live API Key Exposed Through Command-Line Arguments

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (41)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 8)May include surrounding context.

md
allowed-tools: Bash(npx postbridge-cli:*), Bash(postbridge-cli:*), Bash(./scripts/post-bridge.js:*)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 149)May include surrounding context.

Delete media:

text
DELETE /v1/media/<media_id>

Create Post

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 207)May include surrounding context.

Delete Post

text
DELETE /v1/posts/<post_id>

Only works on scheduled/draft posts (cannot delete published posts).

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill uses 'network' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill uses 'shell' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The manifest allowed-tools includes Bash(npx postbridge-cli:*), which authorizes arbitrary subcommands of an unpinned npm package. This is more dangerous than a mere documentation example because it directly expands the agent's executable surface to registry-fetched code.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The manifest explicitly allows execution of npx postbridge-cli:*, which fetches and runs a package from the npm registry without any version pinning or integrity constraint. This creates a supply-chain execution risk: a compromised package, malicious update, typo-squat, or registry/account takeover could lead to arbitrary code execution in the agent's environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

This second match on the same line still corresponds to an unpinned npx postbridge-cli execution path. The risk is unchanged: the agent may execute whatever package version the registry serves at that moment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

This second match on the same line still corresponds to an unpinned npx postbridge-cli execution path. The risk is unchanged: the agent may execute whatever package version the registry serves at that moment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

This duplicate match is the same unpinned npx skills update path. Because updates change installed skill content, compromise here could propagate malicious behavior into future agent runs.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 52)May include surrounding context.

md
## Setup

1. Create a Post Bridge account at [post-bridge.com](https://post-bridge.com)
2. Connect your social accounts (TikTok, Instagram, YouTube, Twitter, etc.)
3. [Enable API access](https://www.post-bridge.com/dashboard/api-keys) (Settings > API)
4. Store your API key in workspace `.env`:

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The setup command uses npx postbridge-cli setup --key ..., which runs an unpinned npm package at the moment sensitive credentials are being handled. A malicious or compromised package version could exfiltrate the provided API key or execute arbitrary local actions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The note again recommends npx postbridge-cli as the preferred path, reinforcing an unpinned remote code execution workflow. Because this is framed as agent guidance, it meaningfully increases the likelihood the unsafe path is chosen.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The example command lists npx postbridge-cli setup --key <key>, again combining unpinned package execution with secret material. This is dangerous because a registry compromise could turn a routine setup step into credential theft or arbitrary code execution.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The accounts example uses an unpinned npx postbridge-cli call. Even read-only listing operations still execute external code locally, so compromise of the package can affect the host regardless of the API action being requested.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This posting example invokes an unpinned npm CLI for a live social-media action. The combination of remote code execution risk and access to real posting credentials makes the impact substantial if the package supply chain is compromised.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The scheduled-post example still executes the same unpinned external package. Because the tool has authority over real accounts and scheduling, compromise could lead to unauthorized posts, data exfiltration, or local code execution.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The queue-scheduling example invokes an unpinned package from npm. The risk is not the queue feature itself but the runtime fetch-and-execute model without version control or integrity guarantees.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This timezone queue example repeats the same unpinned execution pattern. Repetition throughout the skill increases exposure by making unsafe commands the default copied workflow.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The draft example still depends on an unpinned npx postbridge-cli. Draft mode reduces social-account blast radius but does not reduce the host-side risk of executing unreviewed package code.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The platform-config example uses the same unpinned npm execution path. Any compromise in the package can exploit local execution regardless of the complexity of flags passed to it.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The upload example invokes an unpinned package while handling local files destined for external upload. A malicious package version could access additional files or exfiltrate sensitive local content beyond the intended media.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This posting-with-media example repeats the unpinned execution risk. Since it combines account access and media handling, a compromised package could both steal content and misuse posting permissions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The posts listing example is still an unpinned package execution path. Although functionally read-oriented, it executes code with access to local environment variables and configuration, so compromise remains meaningful.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/post-bridge.js:23