Back to skill

Security audit

Social Post Generator

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed social-post generator, but it fetches any user-supplied URL from the agent environment without destination safeguards.

Review before installing if you run agents in a corporate, cloud, or private-network environment. Only pass public article URLs you trust, avoid localhost/private/metadata URLs, and manually review generated posts because much of the output is generic template copy rather than a faithful summary of the source.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/generate.sh:22
Finding

Unrestricted URL Fetching Enables Server-Side Request Forgery in Post Generation

Content
View full analysis
&2 content=$(curl --silent --max-time 20 -L \ -H "User-Agent: Mozilla/5.0" \ "$input" 2>&1) ``` ### Technical Analysis The script passes a user-controlled HTTP or HTTPS URL directly to `curl`. Although the URL is quoted, which prevents shell command injection, its destination is not validated before the network request is made. The `-L` option follows redirects, but neither the original URL nor redirect destinations are checked for loopback, private, link-local, reserved, or cloud metadata addresses. An attacker who can control the input can therefore cause the runtime environment to issue HTTP GET requests to services reachable from the Agent's network context. Fetching public articles is necessary for the declared functionality, but unrestricted access to arbitrary network destinations exceeds the minimum privilege required. ### Attack Path 1. An attacker supplies a URL such as a loopback address, private-network service, cloud metadata address, or attacker-controlled public URL that redirects to one. 2. The script accepts the value because it starts with `http://` or `https://`. 3. `curl -L` connects to the destination and follows redirects without validating the resolved addresses. 4. The internal response is stored in `content` and parsed as article content. 5. Depending on the response format, parts of the response may influence generated output. Even without response disclosure, the request can act as a blind SSRF probe against internal HTTP services. ### Impact Assessment The vulnerability grants access to the network privileges of the environment running the Skill. Potential consequences include: - Blind probing of localhost and internal HTTP services. - Requests ...[truncated 450 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/thread.sh:21
Finding

Unrestricted URL Fetching Enables Server-Side Request Forgery in Thread Generation

Content
View full analysis
&2 content=$(curl --silent --max-time 20 -L \ -H "User-Agent: Mozilla/5.0" \ "$input" 2>&1) ``` ### Technical Analysis The thread generator performs an HTTP request to any user-supplied URL beginning with `http://` or `https://`. It does not validate the hostname, resolved IP address, port, or redirect chain. Because `curl` follows redirects, checking only the initial URL scheme would remain insufficient even if the initial host were trusted. A public attacker-controlled URL can redirect the request to an internal or link-local endpoint. The Skill legitimately requires outbound access to retrieve public articles, but it does not need unrestricted access to localhost, private networks, or infrastructure metadata services. ### Attack Path 1. The attacker provides an internal URL or a public URL under their control. 2. The input passes the script's scheme-only regular-expression check. 3. If a public URL is used, the attacker responds with a redirect to an internal destination. 4. `curl -L` follows the redirect and sends a GET request using the Agent's network access. 5. The response is stored and parsed for title, description, and body content. 6. The attacker may use the behavior for blind network reconnaissance or may attempt to cause response-derived information to appear in the generated thread. ### Impact Assessment Successful exploitation permits HTTP requests from the Skill's execution environment rather than from the attacker's machine. The reachable scope can include: - Services bound to localhost. - Private intranet applications. - Link-local infrastructure endpoints. - Cloud metadata services. - Internal state-changing endpoints that accept unauthenticated GET requ ...[truncated 182 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/hook.sh:21
Finding

Unrestricted URL Fetching Enables Server-Side Request Forgery in Hook Generation

Content
View full analysis
&2 content=$(curl --silent --max-time 20 -L \ -H "User-Agent: Mozilla/5.0" \ "$input" 2>&1) ``` ### Technical Analysis The flagged network behavior sends an HTTP GET request to a user-selected destination. The audit did not find code that collects secrets or intentionally transmits local file contents, environment variables, credentials, or other sensitive values to a remote server. Nevertheless, the request destination is unrestricted. Scheme validation alone does not prevent SSRF, and `curl -L` introduces redirect-based bypasses because redirect targets are not validated. The script can consequently reach network resources that are accessible to the Agent but not necessarily accessible to the user. ### Attack Path 1. An attacker invokes the hook generator with a loopback, private, link-local, or metadata URL. 2. Alternatively, the attacker supplies a public URL that redirects to one of those destinations. 3. The regular expression accepts the URL based only on its HTTP(S) prefix. 4. `curl` issues the request and follows redirects. 5. The response is processed locally for title, description, and body fields. 6. This provides at least blind internal HTTP request capability; response-derived title information may also be printed in generated hook output where parsing succeeds. ### Impact Assessment The primary impact is unauthorized use of the Agent's network position. This may allow internal service discovery, cloud metadata access attempts, or interaction with internal HTTP endpoints. The request does not include application credentials or local sensitive data in its headers or body. Therefore, the pre-scan warning does not represent confirmed direct exfiltration of sensitive ...[truncated 116 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The documented purpose is content repurposing, but the skill behavior includes fetching remote URL content without clearly declared permissions, which expands its trust boundary beyond local text processing. Description-behavior mismatches are dangerous because they can hide network access and mislead users or policy systems into invoking the skill in contexts where external retrieval, prompt injection from fetched pages, or data-handling risks were not expected.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill advertises shell-capable behavior and explicitly requires curl, but it does not declare any tool scope such as permissions or allowed-tools. This creates an authorization gap where reviewers and runtime policy may not have a clear, enforceable boundary around command execution and network access, increasing the chance of unintended remote fetches or shell misuse.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest says the skill should take a blog post URL or text and generate social media posts from it. While the script fetches or reads input content, the output body is mostly hard-coded thread text with only minimal use of the title/description, so the actual behavior does not meaningfully repurpose the source content as claimed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script fetches arbitrary user-supplied URLs with curl and sends network requests without any notice or consent boundary. In a skill context, this can disclose sensitive internal URLs, access patterns, or private resources to remote servers, and if the environment has internal network reachability it can enable SSRF-style access to internal endpoints or metadata services.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The inline comment at L066 states that the following section extracts key points from the body. In reality, lines L069-L073 print predefined advice and never analyze or extract content from the body variable, directly contradicting the documented intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This code performs a network request to a user-supplied URL and ingests the returned content, which can transmit the user's requested target and retrieve external data. While there is a status message saying the article is being fetched, there is no clear safety disclosure in comments or usage text that the script makes outbound HTTP requests to third-party sites.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script will automatically make an outbound request to any user-supplied http/https URL via curl, which transmits the provided input to a remote host without an explicit warning or confirmation. In this skill context, fetching a blog post URL is expected behavior, but it still creates privacy and SSRF-style risk if the skill is run in a sensitive environment where internal or attacker-chosen URLs could be accessed.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.