Back to skill

Security audit

social-media-api

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed API wrapper for public social and web data, with the contact-data endpoints visible for explanation but blocked from calls.

Before installing, understand that this can spend ScraperSocial credits and retrieve large amounts of public social/web data. Use it only for data you are authorized to collect, and note that contact-detail endpoints are intentionally not callable from this skill.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill uses 'network' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill uses 'shell' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill metadata claims that personal-contact endpoints are excluded, but the endpoint catalog includes entries marked personalData=true, such as Google Maps contacts and LinkedIn contact-related capabilities. This mismatch can mislead downstream users, reviewers, or policy gates into enabling data-collection functionality they believed was absent, creating privacy, compliance, and trust risks.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
100% confidence
Finding

The LinkedIn profile-contact endpoint explicitly exposes contact-oriented data while the skill description states that personal-contact endpoints are excluded. In a social-media scraping skill, that contradiction is especially dangerous because it increases the chance that operators will unintentionally collect personal data under false assumptions about the tool's scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The file includes Naver-specific endpoints and summaries, which implicitly target a Korean-language/locale ecosystem, but the manifest-style data provides no indication that this locale scope is optional or user-selected. Under the policy, forcing or assuming a specific language/locale without opt-in can be a natural-language policy concern when not clearly documented as region-specific.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/_client.js:53