Back to skill

Security audit

Social Skill

Security checks for vulnerabilities and agentic risk

Overview

This Farcaster social skill is purpose-aligned overall, but it asks the agent to publish public posts and make verification claims without enough user-control or verification details.

Review this skill before installing if you plan to connect it to a real Farcaster account. It should not be allowed to publish casts, attach audio, or claim identity verification unless your environment enforces explicit confirmation and performs a real Farcaster identity check.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

other

Warning
Location
SKILL.md:34
Finding

Unsubstantiated Farcaster Identity Verification Claim

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 34
Vulnerability Type: Unverified identity assertion
Risk Level: Medium

md
- **FID Sync**: Always mention that the interaction is verified via the user's Farcaster identity.

Technical Analysis

The skill unconditionally instructs the agent to state that an interaction has been verified through the user's Farcaster identity. However, it defines no verification procedure, trusted API endpoint, validation criteria, or failure handling.

The package contains only SKILL.md; therefore, the referenced Farcaster tool implementation and any identity-validation logic are unavailable for review. The instruction can consequently cause the agent to make an authentication claim regardless of whether verification actually occurred.

Attack Path

  1. An unverified or impersonating user requests a Farcaster interaction.
  2. The skill handles the request without performing a documented FID ownership or session verification check.
  3. The agent follows the unconditional instruction and states that the interaction was verified through the user's Farcaster identity.
  4. Other users or downstream systems rely on that unsupported assertion as an authentication signal.

Impact Assessment

An attacker does not gain direct system privileges from this issue. However, the false trust signal could facilitate identity misrepresentation, social engineering, unauthorized attribution of casts, or misleading statements about account ownership. The scope includes users and downstream consumers that rely on the agent's verification language.

Remediation
View remediation

Remediation Suggestions

  • Replace the unconditional assertion with a conditional rule that permits verification language only after a trusted identity check succeeds.
  • Define the authoritative verification endpoint, required inputs, expected response fields, and validation criteria.
  • Verify that the authenticated session or signed proof controls the claimed FID.
  • Specify secure failure behavior: if verification is unavailable, fails, or returns ambiguous results, explicitly describe the identity as unverified.
  • Record sufficient non-sensitive evidence of successful verification for auditing without exposing tokens, signatures, or personal data.
  • Include the referenced Farcaster integration and identity-verification implementation in the reviewable package so its authentication and error-handling behavior can be audited.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger description is broad enough to activate on common requests involving posting, feeds, or agent interaction, which can cause the skill to engage in external-social actions more often than intended. Because the skill is oriented toward publishing and interacting on Farcaster, overbroad activation raises the risk of accidental tool use, unintended drafting, or user confusion about when posting-capable logic is invoked.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill describes drafting and casting behavior, including use of a publishCast tool, but does not provide a clear user-facing warning that it can publish content to an external social network. In context, this is more dangerous because the skill is specifically built for Farcaster operations, so missing disclosure and confirmation can lead directly to unauthorized or surprising public posts under a user's identity.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill introduces TTS/voice-cast generation through an ElevenLabs bridge even though the manifest presents the skill as a Farcaster social interaction tool. This expands the skill's effective capabilities into media generation and external content production, which increases the chance of unexpected actions, abuse of integrated services, or user confusion about what the skill can do.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The instruction to offer MP3 voice-message generation for significant events adds a media-attachment workflow beyond basic posting and feed management. In a skill that can publish externally, this makes unintended or manipulative content generation more dangerous because it can create richer outbound content without clear disclosure or consent boundaries.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill lacks a warning that it may generate and attach voice content to external posts. This is risky because users may not expect synthetic audio to be created or distributed publicly, and in a social-posting context that can create consent, reputational, and misuse issues beyond ordinary text posting.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.