Back to skill

Security audit

Blotato Post Everywhere

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its social-posting purpose, but it handles a powerful posting API key insecurely and can publish or upload media to connected accounts without a required confirmation step.

Review this skill before installing. Use a throwaway or narrowly scoped Blotato API key if possible, do not let the agent store it in TOOLS.md, prefer an environment variable or secret manager, and require an explicit final confirmation before any post, schedule, or local media upload is submitted.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:33
Finding

Persistent Plaintext Storage of the Blotato API Key

Content
View full analysis
API > Generate API Key 2. **Original content** to publish 3. **Platforms** to publish to (`all` or a list such as `twitter linkedin instagram`) 4. **Publishing time** — immediately, at a specified time, or in the next slot Save the API key to `TOOLS.md` after the user provides it (under `### Blotato`). ``` ### Technical Analysis The Skill explicitly instructs the Agent to persist a reusable Blotato API key in `TOOLS.md`. This stores an authentication credential as plaintext in the project or Agent workspace rather than retaining it only for the operation that requires it. Persistent storage is not necessary for the declared publishing functionality and exceeds minimum credential-retention requirements. Depending on the environment, `TOOLS.md` may be exposed through repository commits, workspace synchronization, backups, diagnostic bundles, Agent context loading, or access by other users and processes. No evidence indicates that the Skill attempts to conceal or intentionally exfiltrate the key. Nevertheless, the prescribed storage method creates a credential-disclosure risk. ### Attack Path 1. The user supplies a valid Blotato API key as instructed. 2. The Agent writes the key in plaintext to `TOOLS.md`. 3. The workspace is committed, synchronized, backed up, logged, or read by another user or process. 4. The unauthorized party extracts the key from `TOOLS.md`. 5. The party uses the key against the documented Blotato API endpoints. 6. Subject to the key's server-side permissions, the party enumerates connected accounts or submits posts to them. ### Impact Assessment Exposure of the key may grant access to the victim's Blotato API capabilities. Based on the audited imple ...[truncated 504 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/blotato_post.py:205
Finding

API Key Exposure Through Command-Line Arguments

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The instruction to save the API key lacks any warning that it is a sensitive credential or any safer handling guidance. This can normalize insecure secret management and lead to credential compromise, enabling unauthorized posting, account abuse, or access to associated account data through the external service.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Retaining a user-provided API key in a persistent file is a direct secret-handling flaw. In an agent environment, persistent plaintext storage is especially dangerous because other tools, future tasks, backups, or repository operations may read and disclose the credential well beyond the original posting purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill states that local files will be uploaded via presigned URL and converted into publicly accessible URLs, but it does not prominently warn the user about this external disclosure. That creates a significant risk of unintentionally exposing local or sensitive media outside the user's environment.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/api.md (reported line 26)May include surrounding context.

md
### Schedules
- `GET /schedules` — list future scheduled posts
- `PATCH /schedules/{id}` — update scheduled post
- `DELETE /schedules/{id}` — delete scheduled post

### Schedule Slots
- `GET /schedule/slots` — list recurring time slots

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly instructs the agent to persist the user's Blotato API key in TOOLS.md, which expands exposure of a sensitive credential beyond the immediate task. Persisting secrets in general documentation or workspace files increases the chance of later leakage through logs, repository sync, prompts, or unrelated tool access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill provides commands for immediate and scheduled publication to multiple external social platforms without requiring an explicit confirmation step before sending content out. In this context, accidental publication is a realistic safety risk because actions are irreversible, externally visible, and may affect multiple connected accounts at once.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/api.md (reported line 67)May include surrounding context.

md
| Platform  | targetType    | Required extra fields                                                                 |
|-----------|---------------|---------------------------------------------------------------------------------------|
| Twitter   | twitter       | none                                                                                  |
| LinkedIn  | linkedin      | none (optional: `pageId` for company page)                                            |
| Facebook  | facebook      | `pageId`                                                                              |
| Instagram | instagram     | none (optional: `mediaType`)                                                          |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/api.md (reported line 73)May include surrounding context.

md
| Platform  | targetType    | Required extra fields                                                                 |
|-----------|---------------|---------------------------------------------------------------------------------------|
| Twitter   | twitter       | none                                                                                  |
| LinkedIn  | linkedin      | none (optional: `pageId` for company page)                                            |
| Facebook  | facebook      | `pageId`                                                                              |
| Instagram | instagram     | none (optional: `mediaType`)                                                          |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/api.md (reported line 74)May include surrounding context.

md
| Platform  | targetType    | Required extra fields                                                                 |
|-----------|---------------|---------------------------------------------------------------------------------------|
| Twitter   | twitter       | none                                                                                  |
| LinkedIn  | linkedin      | none (optional: `pageId` for company page)                                            |
| Facebook  | facebook      | `pageId`                                                                              |
| Instagram | instagram     | none (optional: `mediaType`)                                                          |

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code reads a local file and uploads its full contents to a presigned remote URL, which is a safety-relevant data transmission operation. Although there is an upload progress print, there is no clear user-facing warning in the script's documentation or argument help that local files will be sent to Blotato-hosted infrastructure and become public via a returned public URL.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This markdown file documents operations that expose user account information (/users/me, connected accounts) and can publish or delete scheduled content, but it does not include any warning about privacy implications or the impact of modifying live social posts. Under the markdown criteria for missing user warnings, user-data and system-integrity affecting behaviors should be disclosed.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.