Security audit
socialcannon
Security checks for vulnerabilities and agentic risk
Overview
This skill is a disclosed social media publishing integration with real account impact, but its powers match its purpose and it explicitly warns agents to get approval for live or irreversible actions.
Install only if you intend to let an agent help manage real social accounts. Keep the client secret in environment variables, connect only the accounts you want managed, prefer drafts or scheduled posts, and require explicit approval before publishing, replying, deleting posts, disconnecting accounts, or using repurpose post mode.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
