Back to skill

Security audit

XReplyAI - Social Post Manager

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent social-posting integration, but it can publish or schedule public posts and start recurring automated content generation without a strong confirmation requirement in the skill instructions.

Install only if you are comfortable giving this skill authority to create drafts, upload chosen media files, change posting preferences/schedules, and publish or queue posts through your connected XreplyAI accounts. Before using publish, schedule, content-plan, or posting-schedule tools, require the agent to show the exact content, account, platform, and time and wait for your explicit approval.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 706)May include surrounding context.

md
**Threads account not connected:** If publishing to Threads returns a 422, the user has not connected their Threads account. Direct them to XreplyAI Settings to connect it.

**Threads token expired:** If a Threads post returns `THREADS_TOKEN_EXPIRED`, the access token has expired (Threads tokens expire after ~60 days). Direct the user to XreplyAI Settings to reconnect their Threads account.

**Media upload — file not found:** If `xreply_media_upload` cannot read the file, check that the path is correct and accessible. Use an absolute path to avoid ambiguity.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest says the skill can generate, schedule, and publish across X, LinkedIn, Instagram, Threads, Facebook, YouTube, TikTok, Pinterest, Bluesky, and Mastodon. But the documented tool surface shows publishing details and workflow support primarily for X, LinkedIn, and Threads, while some other listed platforms appear only as enum values in post_contents without corresponding generation support, account-listing support, media/upload support, or workflow examples. This creates a semantic mismatch between the broad manifest claim and the actually documented operational scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill exposes publish and scheduling operations that can create immediate real-world side effects on external social platforms, but it does not prominently require explicit user confirmation at the point of action. In agentic environments, this increases the risk of accidental unauthorized posting, reputational harm, or unintended queued content from ambiguous prompts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

Creating or running a content plan triggers asynchronous background generation, which can produce multiple future drafts or scheduled artifacts without an immediate per-post review step. Without a strong warning and confirmation requirement, users may unintentionally enable ongoing automated content creation that has billing, quota, and reputational consequences.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest describes a social-post generation and publishing skill plus preferences and billing management. xreply_short_links_create adds a standalone branded short-link creation feature that is not mentioned in the manifest description and is usable independently of post creation. That is broader than the stated purpose as written.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.