Back to skill

Security audit

Postzee Skill

Security checks for vulnerabilities and agentic risk

Overview

This skill is coherent for Postzee social-media publishing, but it under-scopes credential handling and immediate or bulk public posting controls.

Review this skill before installing if you connect real brand or business accounts. Use a least-privilege Postzee key if available, avoid pasting long-lived secrets into chat, rotate any key already shared, and require an explicit review of channel list, content, media, schedule, and publish mode before any live or all-channel post.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
README.md:34
Finding

Credentials Are Requested in Chat and Embedded in Command-Line Arguments

Content
View full analysis
"Configure Postzee with my API key: pk_your_key_here" Get your API key at [dashboard.postzee.app/settings](https://dashboard.postzee.app/settings). ``` `SKILL.md:15-21`: ```markdown ## Setup (First Time Only) If the MCP server is not configured yet, help the user set it up: 1. **Ask for the MCP URL**: "Copy your MCP URL from https://dashboard.postzee.app/settings → tab 'API Pública' → section 'MCP (Model Context Protocol)'. It looks like: `https://api.postzee.app/mcp/.../sse`" 2. **Configure MCP**: - **Claude Code**: Run `claude mcp add --transport sse postzee ` (paste the full URL) ``` ### Technical Analysis The documented setup procedure instructs users to submit a Postzee API key directly in an agent conversation. Conversations may be retained in local histories, remote service logs, debugging traces, telemetry, transcripts, or support exports. Consequently, the API key can persist outside a purpose-built secret store. The skill also instructs users to place the complete credential-bearing MCP URL directly in a command-line argument. Depending on the operating system and invocation environment, command arguments may be exposed through: - Shell command history - Process-listing utilities - Process-monitoring or endpoint-management software - Agent execution logs and debugging traces - Terminal session recording - CI/CD logs if the setup is automated An MCP URL containing a bearer token or equivalent unguessable credential must be treated as a secret. Supplying it verbatim through an agent conversation or command argument unnecessarily expands the number of systems that can retain or observe it. No hardcoded pr ...[truncated 1815 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (12)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill describes flows that can automatically publish to social media but does not prominently warn users that content may be posted publicly, immediately, and potentially to multiple channels. In this context, lack of warning materially increases the chance of accidental disclosure, brand damage, or posting unreviewed AI-generated media to public accounts.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 24)May include surrounding context.

Or manually:

bash
mkdir -p ~/.claude/skills/postzee
curl -o ~/.claude/skills/postzee/SKILL.md https://raw.githubusercontent.com/Zee-Labs/postzee-skill/main/SKILL.md

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 24)May include surrounding context.

Or manually:

bash
mkdir -p ~/.claude/skills/postzee
curl -o ~/.claude/skills/postzee/SKILL.md https://raw.githubusercontent.com/Zee-Labs/postzee-skill/main/SKILL.md

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 25)May include surrounding context.

bash
mkdir -p ~/.claude/skills/postzee
curl -o ~/.claude/skills/postzee/SKILL.md https://raw.githubusercontent.com/Zee-Labs/postzee-skill/main/SKILL.md

OpenClaw

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 25)May include surrounding context.

bash
mkdir -p ~/.claude/skills/postzee
curl -o ~/.claude/skills/postzee/SKILL.md https://raw.githubusercontent.com/Zee-Labs/postzee-skill/main/SKILL.md

OpenClaw

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README instructs users to paste an API key directly to the agent without any warning about credential exposure, storage, or reuse. In agent environments, secrets provided in chat may be logged, persisted, or exposed to tools, creating a meaningful risk of credential compromise and unauthorized use of the Postzee account.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README promotes generating and posting content to many connected social media accounts but does not clearly warn users that the skill can publish externally on their behalf. In an agent setting, missing consent and action-boundary warnings can lead to unintended posting, reputational harm, or accidental publication to business accounts.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

md
If the MCP server is not configured yet, help the user set it up:

1. **Ask for the MCP URL**: "Copy your MCP URL from https://dashboard.postzee.app/settings → tab 'API Pública' → section 'MCP (Model Context Protocol)'. It looks like: `https://api.postzee.app/mcp/.../sse`"
2. **Configure MCP**:
   - **Claude Code**: Run `claude mcp add --transport sse postzee <MCP_URL>` (paste the full URL)
   - **OpenClaw**: Store the MCP URL via the `primaryEnv` configuration.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The setup trigger uses broad natural-language phrases like "install postzee" or "configure postzee", which can be matched in conversational or quoted context and cause the agent to enter a credential/setup flow unexpectedly. In a skill that asks the user to retrieve and register an MCP URL tied to an API key context, unintended invocation can lead to confusing or unsafe configuration actions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Treating common verbs like "post" or "publish" as default authorization for immediate posting is dangerous because these words frequently appear in exploratory requests, drafts, or hypothetical discussions. In this skill's context, the action creates public social media posts, so an overly broad trigger can cause accidental publication to real accounts without an explicit final consent step.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
94% confidence
Finding

The instruction to "Execute the full flow without asking at each step" authorizes autonomous progression through credit checks, content generation, polling, channel discovery, and posting. In a public-posting skill, reducing user checkpoints makes it more likely the agent will perform consequential actions, including publication, without a meaningful final approval from the user.

Content

Scanner excerpt · SKILL.md (reported line 114)May include surrounding context.

md
## Quick Actions

Execute the full flow without asking at each step:

- **"Generate and post to Instagram"** — credits → enhance → generate (4:5) → poll → channels → post
- **"Create a video for TikTok"** — credits → enhance → generate video (9:16) → poll → channels → post

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The quick action "Post this text to all channels" is a broad bulk-posting trigger that can amplify mistakes across every connected account. Because the skill supports 30+ platforms and instructs execution of the flow with minimal interaction, a misfire could result in immediate mass publication, reputational harm, and difficult rollback.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.