T09 · Insecure Skill Coding Practices
- Location
scripts/onboarding.js:47- Finding
Plaintext Storage of Long-Lived API Secrets and RevenueCat Transaction Data
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a coherent TikTok marketing automation skill, but it needs careful review because it stores powerful API credentials and business data locally, sets up recurring automation, and can make hard-to-reverse analytics changes.
Install only if you are comfortable giving the skill access to social-posting and analytics accounts. Use least-privilege API keys, avoid committing tiktok-marketing/config.json or snapshots, prefer environment variables or a secret manager, review any cron job before enabling it, and manually verify Postiz-to-TikTok release-ID mappings before running --connect.
scripts/onboarding.js:47Plaintext Storage of Long-Lived API Secrets and RevenueCat Transaction Data
scripts/check-analytics.js:107Irreversible TikTok Analytics Association Based Solely on Chronological Ordering
The declared description claims an end-to-end TikTok marketing automation workflow with research, generation, publishing, analytics, and optimization. The actual code chunk only implements one narrow sub-function: adding text overlays to six slideshow images stored locally. It does not access web resources, call APIs, post content, gather analytics, track conversions, or optimize anything. While text overlays are mentioned in the description, the code’s primary behavior is far narrower than the declared overall skill purpose, so the description does not accurately represent what this supplied code chunk actually does.
The declared description presents a broad end-to-end TikTok marketing automation system, but the supplied code only implements a narrow analytics/checking utility. Its primary function is to retrieve TikTok-related Postiz posts, optionally associate unconnected posts with TikTok video IDs, pull analytics metrics, and save a snapshot. Most of the headline capabilities in the description—research, content generation, overlays, posting, cross-posting, conversion tracking, and iterative optimization—are absent from this code chunk. Additionally, the code performs a write action (connecting release IDs through the Postiz API), which is not clearly reflected in the declared description's analytics-tracking framing for this specific behavior. Therefore the description does not accurately represent what this code chunk actually does.
The description claims a broad end-to-end TikTok marketing automation system, but the supplied code only manages a JSON file containing competitor research notes. Its functions are limited to loading/saving competitor-research.json, printing summaries, appending competitor records, and reporting stored gap insights. The header comment explicitly states that the actual research is done elsewhere by an agent using the browser, so even the declared competitor research capability is not implemented in this code chunk. This is a material mismatch in primary purpose and implemented capabilities, not just an incomplete snippet of a larger feature.
The description promises an end-to-end TikTok slideshow marketing automation system, including researching competitors, generating creative assets, adding overlays, posting/cross-posting, tracking analytics, and iterating automatically. The supplied code only implements a subset: analytics collection from Postiz, optional RevenueCat conversion retrieval, local state persistence, funnel diagnostics, and report generation. That subset does fit part of the declared analytics/optimization functionality, but the primary behavior of this chunk is reporting rather than content creation or publishing. There are no undeclared suspicious capabilities beyond the declared analytics integrations; however, there is a material description-to-behavior mismatch because many headline capabilities in the description are not represented in the code and the actual primary purpose is narrower than advertised.
The supplied code chunk implements only one narrow component of the described system: generating six raw slideshow images from prompts via selectable image-generation providers. Its external interactions are limited to image-generation APIs and local filesystem I/O. The declared description presents an end-to-end TikTok marketing automation workflow with research, creative assembly, posting, analytics, and optimization. None of those broader capabilities appear in this code chunk. While image generation is one subset of the declaration, the primary purpose of this specific code is materially narrower than the declared purpose, so the description does not accurately represent what this code chunk actually does.
The declared description promises an end-to-end TikTok marketing automation workflow with competitor research, creative generation, social posting, analytics, and feedback-loop optimization. The supplied code only implements an onboarding helper script: it creates directories and template JSON files, validates presence of required config fields, and prints a setup summary. There are no browser actions, no image generation calls, no Postiz/TikTok API requests, no analytics retrieval, and no optimization logic. While the file structure references concepts like competitors, hooks, cross-posting, and RevenueCat, these are placeholders/config fields rather than implemented capabilities. Therefore the description materially overstates the code’s actual behavior and primary purpose.
The declared description presents a broad end-to-end TikTok marketing automation capability with research, content generation, multi-platform posting, analytics, and optimization. The supplied code only performs one narrow function: it reads six PNG files from a local directory, uploads them to Postiz, creates a TikTok slideshow post (defaulting to draft/privacy SELF_ONLY), and writes simple metadata to a local meta.json file. There is no evidence of browser-based competitor research, AI image creation, text overlay processing, analytics ingestion, conversion tracking, or iterative optimization logic. This is a material description-behavior mismatch because the actual code implements only a small posting subset of the declared system.
The skill instructs storing API keys and secret credentials in configuration without a strong safety warning or safer storage pattern. Plain inclusion of secrets in config files increases the risk of accidental commit, local disclosure, backup leakage, or downstream prompt/tool exposure.
Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.
**Save the agreed prompt style to config as `imageGen.basePrompt`** so every future post uses it.
**Key prompt rules (explain these as they come up, don't lecture):**
- "iPhone photo" + "realistic lighting" = looks real, not AI-generated
- Lock architecture/layout in EVERY slide prompt or each slide looks like a different place
- Include everyday objects (mugs, remotes, magazines) for lived-in feel
Referenced artifact was not completely inspected
Task: Run scripts/daily-report.js --config tiktok-marketing/config.json --days 3
Referenced artifact was not completely inspected
Task: Run scripts/daily-report.js --config tiktok-marketing/config.json --days 3
The sample config stores highly sensitive secrets in plaintext, including OpenAI, Postiz, and RevenueCat keys. In skill ecosystems, config files are often shared, synced, backed up, or committed, so plaintext secret storage creates a direct path to credential theft and account compromise.
Referenced artifact was not completely inspected
Use `scripts/generate-slides.js`:
Referenced artifact was not completely inspected
Use `scripts/generate-slides.js`:
Referenced artifact was not completely inspected
Use `scripts/check-analytics.js` to automate the connection:
Referenced artifact was not completely inspected
Use `scripts/check-analytics.js` to automate the connection:
The skill clearly directs network-capable actions such as browser-based competitor research, API use with Postiz/OpenAI/RevenueCat, and analytics retrieval, but it does not declare corresponding tool scope or permissions. That mismatch weakens user transparency and policy enforcement, making it easier for an agent to perform external actions the user did not explicitly expect.
The invocation text is broad enough to trigger on many generic marketing discussions, which raises the chance that the skill activates in contexts where the user did not intend browser access, posting, analytics, or system setup. Over-broad auto-invocation is dangerous for a skill with external integrations and system-modifying guidance.
The skill tells the agent to verify and install Node.js and native dependencies on the user's system, expanding from marketing workflow guidance into system modification. That increases the blast radius significantly because package installation can alter the host environment, pull untrusted code, and require elevated privileges.
The skill directs installation of another skill and additional software components, creating a transitive trust problem where one skill causes the agent to fetch and enable more code. This can unintentionally broaden permissions and introduce supply-chain risk beyond the original user request.
The skill instructs creation of a persistent daily cron job that continues to run and message the user after setup. Persistent automation is sensitive because it changes system state and can cause repeated network/API actions and data processing without fresh user approval each time.
The cron/reporting workflow includes ongoing report generation and automated user messaging, but the file does not foreground that as a persistent behavior requiring strong consent. Users may not realize they are enabling recurring background actions and notifications.
OS-level package manager commands for Homebrew, apt, and npm instruct the agent to modify the local machine well beyond content creation logic. In a skill context, embedding such commands can normalize broad host changes and create avoidable risk from dependency installation and privilege escalation.
Including sudo-based package installation encourages elevated execution on the user's machine for a non-admin core task. Running package manager commands with root privileges increases the impact of mistakes, malicious package compromise, or command misuse.
>
> **Ubuntu/Debian:**
> ```bash
> sudo apt-get install build-essential libcairo2-dev libpango1.0-dev libjpeg-dev libgif-dev librsvg2-dev
> npm install canvas
> ```
>
The markdown instructs setting up a recurring cron job that fetches external data, generates reports, updates local files, and messages the user, but it does not warn about persistent scheduled execution or repeated filesystem modification. In an agent skill context, unattended recurring actions increase risk because they can continue exfiltrating metadata, consuming API quotas, and altering local state without fresh user awareness.
Detected: suspicious.exposed_secret_literal