Back to skill

Security audit

FB Personal Poster

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly coherent for Facebook posting, but it uses a full Facebook session to publish posts and photos with under-scoped safety controls, including a public-audience change and a dry-run bug that can still post live.

Review before installing. Only use this with a dedicated, protected Facebook cookie file, verify exactly which photos and text will be posted, and do not rely on --dry-run if FB_DRY_RUN=false may be set in the environment. The publisher should remove automatic Public audience selection, add an explicit publish confirmation, and pin dependencies before this is treated as low risk.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/fb_post.py:285
Finding

Command-Line Dry-Run Override Can Still Publish Live Facebook Posts

Content
View full analysis
Remediation
View remediation
dict: ... if dry_run: await page.keyboard.press("Escape") return {"success": True, "dry_run": True} await btn.click() ``` Apply the same change to `post_with_photos()` and invoke the functions with `args.dry_run`. Alternatively, assign the resolved option to the global variable before posting, although explicit parameter passing is safer and easier to test. Avoid changing the environment after configuration has already been read. Add automated tests covering at least these combinations: - No environment setting and no option: dry-run remains enabled. - `FB_DRY_RUN=false` without `--dry-run`: live mode is enabled. - `FB_DRY_RUN=false` with `--dry-run`: posting is blocked. - Both text and photo posting paths honor the same resolved setting. For stronger safety, require an explicit positive option such as `--publish` for all live operations rather than relying only on a false-valued environment variable. ]]>

T08 · Insecure Dependencies

Note
Location
scripts/requirements.txt:1
Finding

Unpinned Executable Browser-Automation Dependency

Content
View full analysis
=1.0.0 ``` The documented installation procedure executes the dependency and uses it to install Chromium: ```bash cd scripts/ && pip install -r requirements.txt python -m patchright install chromium ``` ### Technical Analysis The requirement accepts any Patchright version at or above `1.0.0`. A future version can therefore be selected automatically without review. The installation is also not protected by package hashes or a lock file. This dependency is security-sensitive because it controls the browser process used to load Facebook authentication state. Its code executes with the privileges of the user running the Skill and can potentially access process environment variables, local files available to that user, Facebook cookie data, and the authenticated browser context. No evidence was found that the currently referenced package is malicious. The issue is the unsafe and non-reproducible supply-chain policy, which permits the effective dependency code to change between installations. ### Attack Path 1. A future compromised, malicious, or unexpectedly incompatible release satisfies `patchright>=1.0.0`. 2. A user follows the documented `pip install -r requirements.txt` command. 3. The package resolver installs that release automatically. 4. The user executes `python -m patchright install chromium` or runs `fb_post.py`. 5. Dependency-controlled code executes with the invoking user's permissions. 6. A malicious release could inspect accessible files or environment variables, interact with the Facebook session, or alter browser behavior. Successful exploitation depends on compromise or malicious modification of an accepted upstream release or its distribution path; no ...[truncated 710 chars]
Remediation
View remediation
``` Generate and retain hashes for all resolved distributions, then install with hash verification: ```bash python -m pip install --require-hashes -r requirements.txt ``` Use a lock file or fully resolved requirements file that pins transitive dependencies as well. Obtain packages only from an explicitly configured trusted package index, review updates before changing the lock file, and use automated dependency scanning for known vulnerabilities. Where feasible, isolate installation and execution in a dedicated virtual environment or container with access only to the cookie file, state file, images, and other resources required for the Facebook-posting task. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (10)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code attempts to switch the audience to Public without clear disclosure or consent, converting what may have been a limited-audience personal post into broadly visible content. Combined with text and local photo upload, this materially raises the privacy and reputational risk to the user.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill exposes access to sensitive environment variables and browser/MCP-driven automation capabilities but does not declare any explicit tool scope or permissions boundary. In a credentialed browser-automation skill that handles Facebook session cookies, missing scope declarations increases the chance of unintended tool access, overbroad execution, or secret exposure through the hosting agent.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 40)May include surrounding context.

md
1. Log in to Facebook in Chrome (manually, once)
2. Export all `facebook.com` cookies as JSON via EditThisCookie extension
3. Save to path in `FB_COOKIE_FILE` with `chmod 600`

Cookies last ~30–90 days. Re-export when expired.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 96)May include surrounding context.

md
1. Log in to Facebook in Chrome (manually, once)
2. Export all `facebook.com` cookies as JSON via EditThisCookie extension
3. Save to path in `FB_COOKIE_FILE` with `chmod 600`

Cookies last ~30–90 days. Re-export when expired.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script can publish a Facebook post immediately after composing it, with no final confirmation step at the moment of irreversible action. In an agent setting, this increases the risk of accidental posting of incorrect, sensitive, or manipulated content using the user's authenticated session.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script uploads local photo paths and proceeds toward publication without a distinct warning or approval step covering the files selected for upload. Because the skill operates with browser-authenticated Facebook access, a mistaken or adversarially influenced invocation could leak sensitive local images to a social platform.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The photo-posting flow includes logic to open the sharing controls and select the Public audience, which exceeds the stated capability of posting to a personal timeline. This can silently broaden the visibility of user content and uploaded local photos, causing unintended disclosure to anyone on the internet or Facebook platform.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script contains an unnecessary capability to modify post privacy settings even though the skill description only requires posting content. Extra account-modifying capability increases the blast radius of automation mistakes and creates a path for privacy-impacting behavior that users may not expect.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The Tips section includes Chinese text for key operating guidance, which imposes a specific language on users without stating that the skill is bilingual or offering an English-only alternative. This is a natural-language policy issue because it can restrict usability based on language without user opt-in.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
91% confidence
Finding

The dependency is specified as patchright>=1.0.0, which allows installation of any newer version, including unreviewed releases that may introduce malicious code, breaking changes, or newly disclosed vulnerabilities. In this skill, the package drives browser automation against an authenticated Facebook session, so a compromised or unexpected dependency could access highly sensitive session cookies and account actions.

Content

Scanner excerpt · scripts/requirements.txt (reported line 1)May include surrounding context.

text
patchright>=1.0.0

Static analysis

No suspicious patterns detected.