Back to skill

Security audit

X Post

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward X post drafting helper that writes drafts into an Obsidian-style notes workflow, with the main caution that it may edit local note files when used.

Install this only if you want the agent to create Markdown draft files and update your daily journal as part of drafting X posts. For tighter control, ask the agent to show the draft first and confirm the exact file and journal path before it writes anything.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly directs the agent to save generated content into the Obsidian vault and add a link in today's journal, which causes local file modifications as part of normal execution. While this appears to be intended functionality rather than malicious behavior, it is still a real safety issue because the skill is user-invocable and does not require clear user confirmation or warn that it will write to local notes and alter existing journal content.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.