Back to skill

Security audit

内容自动发布

Security checks for vulnerabilities and agentic risk

Overview

This skill is meant to publish content to public platforms, but it does not clearly define confirmation, account, or cancellation safeguards.

Before installing, confirm that the skill requires explicit approval for each target platform, publish time, and account. Do not use it for private, regulated, or sensitive content unless you know how scheduled posts are stored, canceled, and audited.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill advertises automated posting to multiple external platforms and scheduling, but provides no warning that content will be transmitted to third-party services or may be published automatically at a later time. This can cause unintended disclosure, accidental publication, or misuse if users do not understand the external side effects and persistence of scheduled posts.

Static analysis

No suspicious patterns detected.