Back to skill

Security audit

Postiz is a tool to schedule social media and chat posts to 28+ channels X, LinkedIn, LinkedIn Page, Reddit, Instagram, Facebook Page, Threads, YouTube, Google My Business, TikTok, Pinterest, Dribbble, Discord, Slack, Kick, Twitch, Mastodon, Bluesky, Lemmy, Farcaster, Telegram, Nostr, VK, Medium, Dev.to, Hashnode, WordPress, ListMonk

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent documentation for a Postiz social-posting CLI, but it should be reviewed carefully because it can publish or delete content from connected accounts while relying on unpinned external installation and weak credential-handling guidance.

Review this before installing if you will connect real social, chat, or business accounts. Prefer a pinned and verified CLI version, use OAuth or a proper secret store instead of placing API keys in shell profiles, avoid printing tokens, keep separate credentials for custom/self-hosted API URLs, and require an explicit human approval step before any posts:create, posts:delete, or bulk automation against production accounts.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:659
Finding

Agent-facing instruction promotes an unrelated external Skill

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:9
Finding

Unpinned npm package is installed globally and executed outside the audited artifact

Content
View full analysis
Remediation
View remediation
`. 2. Publish and document integrity or provenance information for the reviewed release. 3. Include the executable CLI source, package manifest, and lockfile in the artifact so credential and network behavior can be audited. 4. Prefer a project-local installation over global installation. 5. Avoid `npx` execution of an unpinned package. 6. Document how users can verify the npm publisher, package signature or provenance, and expected integrity hash. 7. Review package lifecycle scripts and disable them during installation when they are unnecessary. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
HOW_TO_RUN.md:72
Finding

Documentation encourages plaintext API-key persistence and terminal disclosure

Content
View full analysis
> ~/.bashrc # or ~/.zshrc if you use zsh ``` ``` The troubleshooting section also recommends printing the secret: ```markdown ### "POSTIZ_API_KEY is not set" ```bash export POSTIZ_API_KEY=your_key # Verify it's set echo $POSTIZ_API_KEY ``` ``` The persistence recommendation is repeated later: ```markdown **Permanent (add to shell profile):** ```bash # For bash echo 'export POSTIZ_API_KEY=your_key' >> ~/.bashrc source ~/.bashrc # For zsh echo 'export POSTIZ_API_KEY=your_key' >> ~/.zshrc source ~/.zshrc ``` ``` ### Technical Analysis Writing an API key directly into `.bashrc` or `.zshrc` stores it as long-lived plaintext. Shell profile files may be readable by other local processes running as the same user and may be copied into home-directory backups, support archives, dotfile repositories, or workstation synchronization systems. Running `echo $POSTIZ_API_KEY` discloses the complete key in terminal output. That output may be visible during screen sharing or retained in terminal recordings, CI logs, debugging transcripts, or support tickets. The API key is an authentication token used for Postiz operations, so its confidentiality should be protected to the same standard as other account credentials. ### Attack Path 1. A user follows the documented persistence command with a real API key. 2. The key is stored in plaintext in a shell startup file. 3. The shell profile is read through local access, backup access, accidental dotfile publication, or diagnostic collection. 4. Alternatively, the user follows the troubleshooting instr ...[truncated 767 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
PROJECT_STRUCTURE.md:214
Finding

API authentication can be redirected to a user-configurable endpoint without documented trust controls

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (31)

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · HOW_TO_RUN.md (reported line 78)May include surrounding context.

Publishing) 🌐

Once published to npm:

bash
# Install globally
npm install -g postiz

# Or use with npx (no install)
npx postiz --help
npx postiz posts:list

Quick Setup Guide

Step 1: Build the CLI

bash
# From monorepo root
pnpm run build:cli

Step 2: Set Your API Key

bash
export POSTIZ_API_KEY=your_api_key_here

# To make it permanent, add to your shell profile:
echo 'export POSTIZ_API_KEY=your_api_key' >> ~/.bashrc
# or ~/.zshrc if you use zsh

Step 3: Choose Your Method

For quick testing:

bash
node apps/cli/dist/index.js --help

For regular use (recommended):

bash
cd apps/cli
pnpm link --global
postiz --help

Troubleshooting

"Command not found: postiz"

If you linked globally but still get this error:

bash
# Check if it's linked
which postiz

# If not found, try linking again
cd apps/cli
pnpm link --global

# Or check your PATH
echo $PATH

"POSTIZ_API_KEY is not set"

bash
export POSTIZ_API_KEY=y

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
81% confidence
Finding

The documented availability of a raw DELETE /public/v1/posts/:id operation indicates the skill exposes a destructive action that could be triggered with an attacker-supplied or mistaken identifier. In an AI-agent context, lacking documented guardrails such as confirmation, ownership checks, dry-run behavior, or constrained parameter validation increases the risk of unintended deletion through prompt manipulation or user error.

Content

Scanner excerpt · PROJECT_STRUCTURE.md (reported line 253)May include surrounding context.

md
1. **Endpoints Used**
   - `POST /public/v1/posts` - Create post
   - `GET /public/v1/posts` - List posts
   - `DELETE /public/v1/posts/:id` - Delete post
   - `GET /public/v1/integrations` - List integrations
   - `POST /public/v1/upload` - Upload media

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · QUICK_START.md (reported line 69)May include surrounding context.

Log in to your Postiz account at https://postiz.com 2. Navigate to Settings → API Keys 3. Generate a new API key

2. Set Environment Variable

bash
# Bash/Zsh
export POSTIZ_API_KEY=your_api_key_here

# Fish
set -x POSTIZ_API_KEY your_api_key_here

# PowerShell
$env:POSTIZ_API_KEY="your_api_key_here"

To make it permanent, add it to your shell profile:

bash
# ~/.bashrc or ~/.zshrc
echo 'export POSTIZ_API_KEY=your_api_key_here' >> ~/.bashrc
source ~/.bashrc

3. Verify Installation

bash
postiz --help

Basic Commands

Create a Post

bash
# Simple post
postiz posts:create -c "Hello World!" -i "twitter-123"

# Post with multiple images
postiz posts:create \
  -c "Check these out!" \
  -m "img1.jpg,img2.jpg" \
  -i "twitter-123"

# Post with comments (each can have different media!)
postiz posts:create \
  -c "Main post" -m "main.jpg" \
  -c "First comment" -m "comment1.jpg" \
  -c "Second comment" -m "comment2.jpg" \
  -i "twitter-123"

# Scheduled

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 34)May include surrounding context.

This will:

  1. Display a one-time code in your terminal
  2. Open your browser to authorize
  3. Automatically save credentials to ~/.postiz/credentials.json
bash
# Check current auth status (verifies credentials are still valid)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 105)May include surrounding context.

This will:

  1. Display a one-time code in your terminal
  2. Open your browser to authorize
  3. Automatically save credentials to ~/.postiz/credentials.json
bash
# Check current auth status (verifies credentials are still valid)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SUMMARY.md (reported line 123)May include surrounding context.

json
{
  "build:cli": "rm -rf apps/cli/dist && pnpm --filter ./apps/cli run build",
  "publish-cli": "pnpm run --filter ./apps/cli publish"
}

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This documentation describes immediate and scheduled publishing to multiple external social/media platforms, including examples that can post 'now' and to several integrations at once, but it does not clearly warn that using the CLI will perform real actions against connected public accounts. In an AI-agent skill context, that omission is risky because an agent may treat the examples as safe operational guidance and trigger unintended external posts, reputation damage, or disclosure through linked accounts.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · HOW_TO_RUN.md (reported line 33)May include surrounding context.

md
# Now you can use it anywhere!
postiz --help
postiz posts:list
postiz posts:create -c "Hello!" -i "twitter-123"

# To unlink later
pnpm unlink --global

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The guide instructs users to append an API key directly into shell profile files, which creates long-lived plaintext credentials in locations that are commonly backed up, synced, or accidentally exposed. This increases the chance of credential leakage through dotfile sharing, screenshots, shell history workflows, or compromise of the local account.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The sample command creates a post against a real external service but does not clearly warn that it may perform a live action using the user’s configured integration. Users may unintentionally publish public content, causing reputational or operational impact that cannot be easily undone.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · HOW_TO_RUN.md (reported line 234)May include surrounding context.

Create a convenient alias:

bash
# Add to ~/.bashrc or ~/.zshrc
alias pz='postiz'

# Now you can use

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The recommended setup culminates in a content-creation command without stating that it may trigger an irreversible live post. In a social publishing context, the absence of such a warning makes accidental posting materially more dangerous because the tool is explicitly designed to reach many public channels.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This section explicitly promotes a fully automated AI-agent workflow that enumerates tools and then invokes them before creating posts, but it does not warn that the final step can perform live actions on connected third-party accounts. In an agent setting, the absence of a clear side-effect warning and confirmation boundary increases the chance of unintended public posting, account misuse, or triggering actions against the wrong integration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The complete example script uses a real API key and ends by invoking postiz posts:create, which can publish content to external platforms, yet it presents the flow as routine automation without a prominent live-side-effects warning. Because this is framed as copy-pastable agent automation, users may execute it directly and unintentionally post to production social accounts or expose operational account access through unattended scripts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file documents a deletePost() command, which is a destructive operation, but provides no warning that deleting posts may be irreversible or affect user data. Under the markdown-specific warning criteria, skills should disclose behaviors that can impact user data or system state.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · PROJECT_STRUCTURE.md (reported line 251)May include surrounding context.

md
### With Postiz API

1. **Endpoints Used**
   - `POST /public/v1/posts` - Create post
   - `GET /public/v1/posts` - List posts
   - `DELETE /public/v1/posts/:id` - Delete post
   - `GET /public/v1/integrations` - List integrations

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation gives direct examples for creating posts that can immediately publish to real external platforms, but it does not prominently warn that these commands may cause irreversible real-world posting side effects. In an agent skill context, this increases the chance that an automated system or user will execute examples against production integrations unintentionally, causing accidental publication, reputational harm, or disclosure of content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file provides copyable CLI examples that create posts on social platforms such as Reddit, YouTube, X, LinkedIn, Instagram, and TikTok, including public/privacy-related settings. The document does not include any user warning that these commands may publish real content to connected accounts or expose content publicly, which is a relevant safety disclosure for a markdown skill description.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The guide tells users to persist POSTIZ_API_KEY by appending it to ~/.bashrc or ~/.zshrc, but it does not warn that this stores a credential in plaintext on disk and should be protected from sharing or committing. The markdown criteria call for warnings when behavior could affect user privacy or credential safety.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The markdown includes a postiz posts:delete abc123xyz example that performs deletion, but there is no surrounding warning that this removes a post or may be irreversible. Under the markdown criteria, destructive behavior affecting user data should be accompanied by a user-facing warning.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file documents postiz posts:delete <post-id> as a management command but provides no warning that it deletes a post or that the action may be irreversible. For markdown files, safety-relevant behaviors that can affect user data should include a clear disclosure so users and agents understand the risk before invoking the command.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.