Back to skill

Security audit

Facebook Graph API Skill (Secure)

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only Facebook Page API skill whose token use and content-management actions are disclosed and aligned with its stated purpose.

Install only if you intend to let an agent help with Facebook Page publishing or moderation. Treat FB_APP_SECRET and FB_ACCESS_TOKEN as live credentials, prefer Authorization headers over query-string tokens, use the narrowest Page permissions possible, and confirm targets before deleting posts or comments.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (20)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/comments-moderation.md (reported line 19)May include surrounding context.

md
## 4) Hide or delete a comment
- Hide: `POST /{comment-id}` with `is_hidden=true`
- Delete: `DELETE /{comment-id}`

## 5) Moderation workflow
- Validate comment text.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/graph-api-overview.md (reported line 12)May include surrounding context.

md
- HTTP GET for reads.
- HTTP POST for creates/updates.
- HTTP DELETE for deletes (where supported).
- Access token in query (`access_token`) or `Authorization: Bearer` header.

## 3) Page publishing flow (high level)
- Obtain user access token with required scopes.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/graph-api-overview.md (reported line 17)May include surrounding context.

md
# HTTP Request Templates (Graph API)

## Authentication
All requests must include a valid access token. You can pass it either:
- As a query parameter: `?access_token=YOUR_TOKEN`
- Or as an HTTP header: `Authorization: Bearer YOUR_TOKEN`

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/http-request-templates.md (reported line 4)May include surrounding context.

md
# HTTP Request Templates (Graph API)

## Authentication
All requests must include a valid access token. You can pass it either:
- As a query parameter: `?access_token=YOUR_TOKEN`
- Or as an HTTP header: `Authorization: Bearer YOUR_TOKEN`

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/page-posting.md (reported line 36)May include surrounding context.

md
# HTTP Request Templates (Graph API)

## Authentication
All requests must include a valid access token. You can pass it either:
- As a query parameter: `?access_token=YOUR_TOKEN`
- Or as an HTTP header: `Authorization: Bearer YOUR_TOKEN`

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/permissions-and-tokens.md (reported line 5)May include surrounding context.

md
# HTTP Request Templates (Graph API)

## Authentication
All requests must include a valid access token. You can pass it either:
- As a query parameter: `?access_token=YOUR_TOKEN`
- Or as an HTTP header: `Authorization: Bearer YOUR_TOKEN`

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/permissions-and-tokens.md (reported line 15)May include surrounding context.

md
# HTTP Request Templates (Graph API)

## Authentication
All requests must include a valid access token. You can pass it either:
- As a query parameter: `?access_token=YOUR_TOKEN`
- Or as an HTTP header: `Authorization: Bearer YOUR_TOKEN`

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/permissions-and-tokens.md (reported line 27)May include surrounding context.

md
# HTTP Request Templates (Graph API)

## Authentication
All requests must include a valid access token. You can pass it either:
- As a query parameter: `?access_token=YOUR_TOKEN`
- Or as an HTTP header: `Authorization: Bearer YOUR_TOKEN`

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/page-posting.md (reported line 33)May include surrounding context.

md
## 5) Update or delete
- Update post: `POST /{post-id}` (fields you want to change)
- Delete post: `DELETE /{post-id}`

## Notes
- Page access token required for publish actions.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

md
# Permissions and Tokens

## 1) Token types
- User access token (granted via OAuth).
- Page access token (used for Page content actions).

## 2) Common Page permissions

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

md
# Permissions and Tokens

## 1) Token types
- User access token (granted via OAuth).
- Page access token (used for Page content actions).

## 2) Common Page permissions

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 62)May include surrounding context.

md
# Permissions and Tokens

## 1) Token types
- User access token (granted via OAuth).
- Page access token (used for Page content actions).

## 2) Common Page permissions

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 67)May include surrounding context.

md
# Permissions and Tokens

## 1) Token types
- User access token (granted via OAuth).
- Page access token (used for Page content actions).

## 2) Common Page permissions

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/graph-api-overview.md (reported line 15)May include surrounding context.

md
# Permissions and Tokens

## 1) Token types
- User access token (granted via OAuth).
- Page access token (used for Page content actions).

## 2) Common Page permissions

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/permissions-and-tokens.md (reported line 4)May include surrounding context.

md
# Permissions and Tokens

## 1) Token types
- User access token (granted via OAuth).
- Page access token (used for Page content actions).

## 2) Common Page permissions

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/security-and-secrets.md (reported line 35)May include surrounding context.

md
# Permissions and Tokens

## 1) Token types
- User access token (granted via OAuth).
- Page access token (used for Page content actions).

## 2) Common Page permissions

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file documents a delete operation for comments but does not warn that deletion may be irreversible or affect user data. For markdown files, safety-impacting behaviors should include clear disclosure when they can modify or remove content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file documents moderation and deletion operations such as hiding and deleting comments, but it does not include any warning that these actions affect live user-visible content and may be irreversible. Under the markdown-specific warning criterion, user-impacting actions should be accompanied by a clear disclosure about data or system integrity impact.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file describes how to delete a post via DELETE /{post-id} but does not include any warning that the action is destructive or may be irreversible. For markdown files, user-facing documentation should warn about behaviors that can affect user data or system integrity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This markdown file explains passing an access_token and obtaining user and Page access tokens, but it does not include any warning that these tokens are sensitive credentials that should be protected and not exposed in logs, URLs, or shared output. Because markdown files should warn about behaviors affecting privacy or system integrity, the omission is a quality/safety concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.