T01 · Skill Instruction Hijacking
- Location
SKILL.md:659- Finding
Agent-facing instruction promotes an unrelated external Skill
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is coherent documentation for a Postiz social-posting CLI, but it should be reviewed carefully because it can publish or delete content from connected accounts while relying on unpinned external installation and weak credential-handling guidance.
Review this before installing if you will connect real social, chat, or business accounts. Prefer a pinned and verified CLI version, use OAuth or a proper secret store instead of placing API keys in shell profiles, avoid printing tokens, keep separate credentials for custom/self-hosted API URLs, and require an explicit human approval step before any posts:create, posts:delete, or bulk automation against production accounts.
SKILL.md:659Agent-facing instruction promotes an unrelated external Skill
SKILL.md:9Unpinned npm package is installed globally and executed outside the audited artifact
HOW_TO_RUN.md:72Documentation encourages plaintext API-key persistence and terminal disclosure
PROJECT_STRUCTURE.md:214API authentication can be redirected to a user-configurable endpoint without documented trust controls
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
Publishing) 🌐
Once published to npm:
# Install globally
npm install -g postiz
# Or use with npx (no install)
npx postiz --help
npx postiz posts:list
# From monorepo root
pnpm run build:cli
export POSTIZ_API_KEY=your_api_key_here
# To make it permanent, add to your shell profile:
echo 'export POSTIZ_API_KEY=your_api_key' >> ~/.bashrc
# or ~/.zshrc if you use zsh
For quick testing:
node apps/cli/dist/index.js --help
For regular use (recommended):
cd apps/cli
pnpm link --global
postiz --help
If you linked globally but still get this error:
# Check if it's linked
which postiz
# If not found, try linking again
cd apps/cli
pnpm link --global
# Or check your PATH
echo $PATH
export POSTIZ_API_KEY=y
The documented availability of a raw DELETE /public/v1/posts/:id operation indicates the skill exposes a destructive action that could be triggered with an attacker-supplied or mistaken identifier. In an AI-agent context, lacking documented guardrails such as confirmation, ownership checks, dry-run behavior, or constrained parameter validation increases the risk of unintended deletion through prompt manipulation or user error.
1. **Endpoints Used**
- `POST /public/v1/posts` - Create post
- `GET /public/v1/posts` - List posts
- `DELETE /public/v1/posts/:id` - Delete post
- `GET /public/v1/integrations` - List integrations
- `POST /public/v1/upload` - Upload media
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
Log in to your Postiz account at https://postiz.com 2. Navigate to Settings → API Keys 3. Generate a new API key
# Bash/Zsh
export POSTIZ_API_KEY=your_api_key_here
# Fish
set -x POSTIZ_API_KEY your_api_key_here
# PowerShell
$env:POSTIZ_API_KEY="your_api_key_here"
To make it permanent, add it to your shell profile:
# ~/.bashrc or ~/.zshrc
echo 'export POSTIZ_API_KEY=your_api_key_here' >> ~/.bashrc
source ~/.bashrc
postiz --help
# Simple post
postiz posts:create -c "Hello World!" -i "twitter-123"
# Post with multiple images
postiz posts:create \
-c "Check these out!" \
-m "img1.jpg,img2.jpg" \
-i "twitter-123"
# Post with comments (each can have different media!)
postiz posts:create \
-c "Main post" -m "main.jpg" \
-c "First comment" -m "comment1.jpg" \
-c "Second comment" -m "comment2.jpg" \
-i "twitter-123"
# Scheduled
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
This will:
~/.postiz/credentials.json# Check current auth status (verifies credentials are still valid)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
This will:
~/.postiz/credentials.json# Check current auth status (verifies credentials are still valid)
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
{
"build:cli": "rm -rf apps/cli/dist && pnpm --filter ./apps/cli run build",
"publish-cli": "pnpm run --filter ./apps/cli publish"
}
This documentation describes immediate and scheduled publishing to multiple external social/media platforms, including examples that can post 'now' and to several integrations at once, but it does not clearly warn that using the CLI will perform real actions against connected public accounts. In an AI-agent skill context, that omission is risky because an agent may treat the examples as safe operational guidance and trigger unintended external posts, reputation damage, or disclosure through linked accounts.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
# Now you can use it anywhere!
postiz --help
postiz posts:list
postiz posts:create -c "Hello!" -i "twitter-123"
# To unlink later
pnpm unlink --global
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
The guide instructs users to append an API key directly into shell profile files, which creates long-lived plaintext credentials in locations that are commonly backed up, synced, or accidentally exposed. This increases the chance of credential leakage through dotfile sharing, screenshots, shell history workflows, or compromise of the local account.
The sample command creates a post against a real external service but does not clearly warn that it may perform a live action using the user’s configured integration. Users may unintentionally publish public content, causing reputational or operational impact that cannot be easily undone.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
Create a convenient alias:
# Add to ~/.bashrc or ~/.zshrc
alias pz='postiz'
# Now you can use
The recommended setup culminates in a content-creation command without stating that it may trigger an irreversible live post. In a social publishing context, the absence of such a warning makes accidental posting materially more dangerous because the tool is explicitly designed to reach many public channels.
This section explicitly promotes a fully automated AI-agent workflow that enumerates tools and then invokes them before creating posts, but it does not warn that the final step can perform live actions on connected third-party accounts. In an agent setting, the absence of a clear side-effect warning and confirmation boundary increases the chance of unintended public posting, account misuse, or triggering actions against the wrong integration.
The complete example script uses a real API key and ends by invoking postiz posts:create, which can publish content to external platforms, yet it presents the flow as routine automation without a prominent live-side-effects warning. Because this is framed as copy-pastable agent automation, users may execute it directly and unintentionally post to production social accounts or expose operational account access through unattended scripts.
This markdown file documents a deletePost() command, which is a destructive operation, but provides no warning that deleting posts may be irreversible or affect user data. Under the markdown-specific warning criteria, skills should disclose behaviors that can impact user data or system state.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
### With Postiz API
1. **Endpoints Used**
- `POST /public/v1/posts` - Create post
- `GET /public/v1/posts` - List posts
- `DELETE /public/v1/posts/:id` - Delete post
- `GET /public/v1/integrations` - List integrations
The documentation gives direct examples for creating posts that can immediately publish to real external platforms, but it does not prominently warn that these commands may cause irreversible real-world posting side effects. In an agent skill context, this increases the chance that an automated system or user will execute examples against production integrations unintentionally, causing accidental publication, reputational harm, or disclosure of content.
This markdown file provides copyable CLI examples that create posts on social platforms such as Reddit, YouTube, X, LinkedIn, Instagram, and TikTok, including public/privacy-related settings. The document does not include any user warning that these commands may publish real content to connected accounts or expose content publicly, which is a relevant safety disclosure for a markdown skill description.
The guide tells users to persist POSTIZ_API_KEY by appending it to ~/.bashrc or ~/.zshrc, but it does not warn that this stores a credential in plaintext on disk and should be protected from sharing or committing. The markdown criteria call for warnings when behavior could affect user privacy or credential safety.
The markdown includes a postiz posts:delete abc123xyz example that performs deletion, but there is no surrounding warning that this removes a post or may be irreversible. Under the markdown criteria, destructive behavior affecting user data should be accompanied by a user-facing warning.
This markdown file documents postiz posts:delete <post-id> as a management command but provides no warning that it deletes a post or that the action may be irreversible. For markdown files, safety-relevant behaviors that can affect user data should include a clear disclosure so users and agents understand the risk before invoking the command.
No suspicious patterns detected.