Back to skill

Security audit

mellow-hub

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed social-publishing integration with meaningful user-control safeguards and no hidden local code or persistence.

Install only if you intend to let an agent work with Mellow Hub and connected social accounts. Use review mode or narrow OAuth/API-key scopes unless you explicitly want autopilot publishing, keep API keys in environment variables, and remember that validation and publishing send draft content and media details to Mellow Hub.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 250)May include surrounding context.

md
| `GET /whoami` | `channels:read` | Same payload as the MCP tool |
| `GET /channels` | `channels:read` | `?refresh=true` re-reads from the provider |
| `POST /channels` | `channels:connect` | Returns the URL a person opens |
| `DELETE /channels/{id}` | `channels:connect` | Disconnect |
| `POST /media` | `media:write` | JSON `{ "url" }` = the `register_media` HEAD check; multipart `file` part ≤ 4 MB = inline upload in one hop |
| `POST /media/upload-url` | `media:write` | Signed PUT target for large files and video |
| `POST /validate` | `posts:read` | `{ ok, issues, notes }`; HTTP 200 even when `ok: false` |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 258)May include surrounding context.

md
| `POST /posts` | `posts:write`, `posts:publish` | `Idempotency-Key` header or `idempotencyKey` body; 201 on create **and** on idempotent replay |
| `GET /posts/{id}` | `posts:read` | Per-target results |
| `PATCH /posts/{id}` | `posts:write` | Reschedule (`scheduledAt`) |
| `DELETE /posts/{id}` | `posts:write` | Cancel |
| `POST /posts/{id}/approve` | `posts:publish`, **signed-in person only** | Agents receive `approval_requires_person` |
| `GET /metrics` | `metrics:read` | `?channelId=…&limit=…` |
| `GET /platforms`, `GET /pricing` | none | Public JSON |

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill description says to use the skill whenever asked to publish to social networks, cross-post, schedule posts, or check a post against network rules, which is broad enough to trigger on generic social-media requests without first establishing user intent, account scope, or whether immediate publication is desired. In this context, the tool can perform real external actions, so over-broad invocation increases the chance of unintended posting or disclosure to third-party services.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 188)May include surrounding context.

md
| Code | Where | What to do |
| --- | --- | --- |
| `subscription_required` (402) | `create_post` unless `draft` | Stop. Relay the message and the upgrade URL from `whoami` (`https://www.mellow.world/hub/pricing`) to the person. Connecting, drafting, validating and previewing keep working. |
| `monthly_limit_reached` (402) | `create_post` | The plan's publications for this month are spent (a post counts once per destination). Publish to fewer networks, wait for the month, or the person changes plan. Never split the post to sneak under the limit without asking. |
| `daily_limit_reached` (429) | `create_post` | This credential's rolling-24-hour ceiling is used up (drafts and cancelled posts count too). Stop and tell the person; only the owner can raise it. |
| `invalid_request` with `issues[]` (400) — the audit journal calls this `validation_failed` | `create_post` | You skipped or ignored `validate_post`. Fix every listed issue (each names the channel and field), validate again, then create. |
| `insufficient_scope` (403) | any tool | The credential lacks that permission. Ask the owner to grant it when creating the key or approving the connection; do not retry. |

External Transmission

Medium
Category
Data Exfiltration
Confidence
83% confidence
Finding

The documented curl examples transmit post content and authorization credentials to an external service, which is inherently sensitive because user-provided text, media URLs, scheduling details, and metadata leave the local environment. Although this is expected for a publishing skill, it remains a real data-exfiltration boundary and becomes dangerous if invoked on ambiguous requests or with sensitive draft content.

Content

Scanner excerpt · SKILL.md (reported line 268)May include surrounding context.

post.example.json first — the spc_… ids and the media URL are placeholders):

sh
curl --fail-with-body https://www.mellow.world/api/hub/v1/validate \
  -H "Authorization: Bearer $MELLOW_HUB_KEY" \
  -H "Content-Type: application/json" \
  --data-binary @post.json

Static analysis

No suspicious patterns detected.