Back to skill

Security audit

publish to all your social media!

Security checks for vulnerabilities and agentic risk

Overview

This skill is purpose-aligned for Fedica posting, but it needs Review because it uses authenticated public-posting automation with a default no-sandbox browser launch and an unpinned global npm tool install.

Install only if you are comfortable with an agent controlling an authenticated Fedica session for public social posting. Prefer a pinned, local or isolated `agent-browser` install, run the browser with sandboxing enabled when possible, and require explicit confirmation of final text, target platforms, and local scheduled time before any post, schedule, or update action.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:14
Finding

Unpinned Global Installation of a Third-Party Browser Automation Package

Content
View full analysis
Remediation
View remediation
``` 2. Maintain and verify a lockfile and npm integrity metadata. 3. Document the expected package publisher and official registry source. 4. Prefer a project-local installation or an isolated execution environment over a global installation. 5. Disable npm lifecycle scripts during installation where compatible: ```bash npm install --ignore-scripts --save-exact agent-browser@ ``` 6. Review the package and required lifecycle scripts before enabling any installation scripts. 7. Run the dependency with a dedicated, least-privileged account or inside a disposable container. 8. Establish an upgrade process that reviews changelogs, package provenance, and dependency changes before changing the pinned version. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:42
Finding

Authenticated Browser Launched with Chromium Sandbox Disabled

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest describes a browser-driven posting/scheduling skill for Fedica, but the documentation explicitly tells the operator to source credentials from env vars, password managers, or files under ~/.secrets. Accessing external secret sources is not implemented browser automation itself and is not declared as part of the skill's stated scope.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest scope is composing and scheduling posts, plus related editing/rescheduling behavior. Calling out the delete handler exposes an additional destructive capability not justified by the stated purpose, especially since deletion is not necessary to compose or schedule content.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.