Back to skill

Security audit

SocialClaw - Social Claw is a social media scheduling skill for AI agents posting to X, LinkedIn, Instagram, Facebook Pages, TikTok, Discord, Telegram, YouTube, Reddit, WordPress, and Pinterest

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real social publishing skill, but it needs Review because it handles posting credentials and live publishing actions without enough safety guardrails.

Install only if you trust SocialClaw and are comfortable with an agent-assisted tool that can affect real public social accounts. Use test workspaces/accounts first, require explicit confirmation before applying schedules or publishing, avoid pasting real keys or webhook URLs into chat or command history, and prefer pinned or isolated CLI installation if you use the optional npm client.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:69
Finding

Unpinned Global Installation of a Third-Party npm CLI

Content
View full analysis
Remediation
View remediation
``` 2. Include and verify the expected npm package integrity digest or signed provenance before installation. 3. Document the verified package publisher, registry, source repository, and release-signing process. 4. Prefer a project-local or isolated installation over a global installation. 5. Where operationally possible, disable lifecycle scripts during installation and separately review any required installation steps: ```bash npm install --ignore-scripts socialclaw@ ``` 6. Review each dependency update before changing the pinned version. 7. Consider bundling a reviewed client implementation or using the documented HTTPS API directly, avoiding unnecessary execution of external package code. 8. Explicitly warn users not to run the installation as root or through `sudo`. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:83
Finding

Sensitive Credentials Passed Through Command-Line Arguments

Content
View full analysis
``` ``` `SKILL.md:136-146`: ```markdown Connect Telegram manually with a bot token and chat target: ```bash socialclaw accounts connect --provider telegram --bot-token --chat-id @yourchannel --json ``` Connect Discord manually with a channel webhook URL: ```bash socialclaw accounts connect --provider discord --webhook-url --json ``` ``` `references/cli.md:23-28`: ```markdown Use the dashboard to create a workspace API key, then log in: ```bash socialclaw login --api-key ``` This stores the key locally and uses `https://getsocialclaw.com` by default. ``` `references/cli.md:74-84`: ```markdown Connect Telegram manually with a bot token and chat target: ```bash socialclaw accounts connect --provider telegram --bot-token --chat-id @yourchannel --json ``` Use a numeric `chat_id` when posting into a group/supergroup that does not expose a stable username. Connect Discord manually with a channel webhook URL: ```bash socialclaw accounts connect --provider discord --webhook-url --json ``` ``` `claude/socialclaw.md:133-144`: ```markdown ```bash socialclaw accounts list --json socialclaw accounts capabilities --account-id --json socialclaw accounts settings --account-id --json socialclaw accounts actions --account-id --json socialclaw accounts connect --provider --open socialclaw accounts connect --provider telegram --bot-token --chat-id @yourchannel --js ...[truncated 3327 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (17)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill includes examples that handle a workspace API key via shell export, CLI login, and HTTP Authorization headers, but it does not explicitly warn users not to paste secrets into chat, commit them to files, or expose them in shell history/logs. In a skill designed for agent-assisted execution, that omission increases the chance that sensitive credentials are revealed to the agent, terminal history, screenshots, or shared transcripts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manual connection flow for Telegram bot tokens and Discord webhook URLs omits any warning that these values are highly sensitive and effectively grant posting capability. If exposed in chat, logs, scripts, or command history, an attacker could abuse them to send unauthorized messages, spam channels, or impersonate the workspace's social accounts.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill enables implicit invocation without tightly scoped trigger conditions, which can cause the agent to call a social-media publishing integration based on vague user intent. Because this skill can connect accounts, upload media, validate schedules, and inspect publishing state across many external platforms, unintended invocation could lead to unwanted actions, data exposure, or accidental posting.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill instructs users to store a workspace API key locally via environment variable and CLI login, but it does not warn that the CLI may persist the key on disk or that shell history/process listings can expose secrets if commands are entered unsafely. Because this skill is explicitly about operating a hosted third-party service, the missing credential-safety guidance increases the chance of inadvertent secret disclosure.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · claude/socialclaw.md (reported line 86)May include surrounding context.

Otherwise validate the key over HTTP:

bash
curl -sS \
  -H "Authorization: Bearer $SC_API_KEY" \
  "https://getsocialclaw.com/v1/keys/validate"

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 110)May include surrounding context.

md
1. Start by confirming the user has a SocialClaw workspace API key.
2. If the user does not have a key yet, send them to `https://getsocialclaw.com/dashboard` to sign in with Google and create one.
3. A workspace API key alone is not sufficient for execution. If billing-related errors appear, route the user to pricing or dashboard billing instead of retrying commands.
4. Never ask the user for provider app secrets. End users connect accounts inside SocialClaw.
5. Prefer explicit provider and account-type language:
   - Facebook Pages, not Facebook personal profiles
   - Instagram Business linked to a Facebook Page

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · claude/socialclaw.md (reported line 101)May include surrounding context.

md
1. Start by confirming the user has a SocialClaw workspace API key.
2. If the user does not have a key yet, send them to `https://getsocialclaw.com/dashboard` to sign in with Google and create one.
3. A workspace API key alone is not sufficient for execution. If billing-related errors appear, route the user to pricing or dashboard billing instead of retrying commands.
4. Never ask the user for provider app secrets. End users connect accounts inside SocialClaw.
5. Prefer explicit provider and account-type language:
   - Facebook Pages, not Facebook personal profiles
   - Instagram Business linked to a Facebook Page

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manual Telegram bot token and Discord webhook connection examples ask the operator to provide highly sensitive credentials directly to commands and HTTP payloads without any warning about their secrecy or the consequences of exposure. Leaked bot tokens or webhook URLs can allow unauthorized posting, spam, impersonation, or abuse of connected channels, which is especially risky in a social publishing skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation tells users to log in with a workspace API key and notes that the key is stored locally, but it does not warn about the security implications of local credential storage such as exposure through shared machines, shell history, backups, or weak filesystem permissions. In an agent skill context, this is more dangerous because agents may run on multi-tenant or semi-automated environments where locally persisted secrets can be accessed by other processes or operators.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manual connection examples instruct users to provide highly sensitive third-party credentials such as Telegram bot tokens and Discord webhook URLs without warning that these values grant posting capability and must be protected. In this social publishing skill, those secrets enable direct message publication to external platforms, so accidental disclosure could let an attacker impersonate the user or automate unauthorized posts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation presents destructive operations such as account disconnection and asset deletion without any caution about permanence, service interruption, or downstream posting failures. In a social media automation environment, an agent or user could remove connected accounts or media needed by scheduled campaigns, causing operational disruption or unintended loss of content availability.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The schedule validation, apply, and publish-draft commands are documented without warning that they can cause real scheduling changes or live publication to user-connected social accounts. In this skill's context, that omission is especially risky because the entire purpose of the tool is cross-platform publishing, so misuse can lead to immediate reputational, operational, or compliance impact across multiple public channels.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation instructs users to connect Telegram posting with a bot token and chat identifiers but does not warn that the bot token is a sensitive secret that enables message posting and bot control within its granted scope. In an agent skill context, omission of credential-handling guidance increases the chance that users paste secrets into prompts, logs, or shared workspace configuration, leading to credential leakage and unauthorized posting.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

A Discord webhook URL is effectively a bearer secret: anyone with the URL can post to the bound channel, and sometimes trigger spam, impersonation, or operational abuse. By describing webhook-based posting without clearly labeling the URL as sensitive, the skill materially increases the risk that users expose it in prompts or stored notes, especially in agent workflows where inputs may be logged or replayed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The workflow instructs users to export and use a workspace API key, and later includes examples for Telegram bot tokens and Discord webhook URLs, but it does not include any warning about treating these values as secrets. In an agent-skill context, this is risky because users may paste live credentials into prompts, terminals, logs, or shared environments, increasing the chance of credential leakage and unauthorized account access.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/workflows.md (reported line 33)May include surrounding context.

Validate key

bash
curl -sS \
  -H "Authorization: Bearer $SC_API_KEY" \
  "https://getsocialclaw.com/v1/keys/validate"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The post-application step calls a live state-changing endpoint that can schedule or publish content, but the documentation does not clearly warn that this is a real execution action rather than a dry run. In an agent setting, this raises the risk of accidental posting, unintended campaign changes, or misuse if a user follows the example without realizing it has production effects.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.