Back to skill

Security audit

Larry

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent TikTok marketing automation skill, but it needs careful review because it stores powerful API credentials and business data locally, sets up recurring automation, and can make hard-to-reverse analytics changes.

Install only if you are comfortable giving the skill access to social-posting and analytics accounts. Use least-privilege API keys, avoid committing tiktok-marketing/config.json or snapshots, prefer environment variables or a secret manager, review any cron job before enabling it, and manually verify Postiz-to-TikTok release-ID mappings before running --connect.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/onboarding.js:47
Finding

Plaintext Storage of Long-Lived API Secrets and RevenueCat Transaction Data

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/check-analytics.js:107
Finding

Irreversible TikTok Analytics Association Based Solely on Chronological Ordering

Content
View full analysis
0) { // TikTok IDs are sequential (higher = newer). Sort ascending. const videoIds = tiktokVideos.map(v => v.id).sort(); // Get already-connected IDs to exclude them const connectedIds = new Set(connected.map(p => p.releaseId)); const availableIds = videoIds.filter(id => !connectedIds.has(id)); console.log(` Found ${videoIds.length} TikTok videos, ${availableIds.length} unconnected\n`); // Sort unconnected posts by publish date (oldest first) // Sort available IDs ascending (oldest first) // Match them up chronologically const sortedAvailable = availableIds.sort(); // We need to match the N most recent available IDs to the N unconnected posts // Take the last N available IDs (newest) to match with the unconnected posts const idsToUse = sortedAvailable.slice(-connectableUnconnected.length); for (let i = 0; i < connectableUnconnected.length; i++) { const post = connectableUnconnected[i]; const videoId = idsToUse[i]; if (!videoId) { console.log(` ⚠️ No matching video ID for "${(post.content || '').substring(0, 50)}..."`); continue; } console.log(` 🔗 Connecting: "${(post.content || '').substring(0, 50)}..."`); console.log(` Post: ${post.id} (${post.publishDate})`); console.log(` TikTok: ${videoId}`); const result = await api( 'PUT', `/posts/${post.id}/release-id`, { releaseId: videoId } ); if (result.releaseId === videoId) { console.log(` ✅ Connected`); } else { console.log(` ⚠️ Connection returned: ${JSON.stringify(result.releaseId)}`); } await sleep(1000); } } ``` ### Technical Analysis When invoked with `--connect`, ...[truncated 2734 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (48)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description claims an end-to-end TikTok marketing automation workflow with research, generation, publishing, analytics, and optimization. The actual code chunk only implements one narrow sub-function: adding text overlays to six slideshow images stored locally. It does not access web resources, call APIs, post content, gather analytics, track conversions, or optimize anything. While text overlays are mentioned in the description, the code’s primary behavior is far narrower than the declared overall skill purpose, so the description does not accurately represent what this supplied code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents a broad end-to-end TikTok marketing automation system, but the supplied code only implements a narrow analytics/checking utility. Its primary function is to retrieve TikTok-related Postiz posts, optionally associate unconnected posts with TikTok video IDs, pull analytics metrics, and save a snapshot. Most of the headline capabilities in the description—research, content generation, overlays, posting, cross-posting, conversion tracking, and iterative optimization—are absent from this code chunk. Additionally, the code performs a write action (connecting release IDs through the Postiz API), which is not clearly reflected in the declared description's analytics-tracking framing for this specific behavior. Therefore the description does not accurately represent what this code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The description claims a broad end-to-end TikTok marketing automation system, but the supplied code only manages a JSON file containing competitor research notes. Its functions are limited to loading/saving competitor-research.json, printing summaries, appending competitor records, and reporting stored gap insights. The header comment explicitly states that the actual research is done elsewhere by an agent using the browser, so even the declared competitor research capability is not implemented in this code chunk. This is a material mismatch in primary purpose and implemented capabilities, not just an incomplete snippet of a larger feature.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The description promises an end-to-end TikTok slideshow marketing automation system, including researching competitors, generating creative assets, adding overlays, posting/cross-posting, tracking analytics, and iterating automatically. The supplied code only implements a subset: analytics collection from Postiz, optional RevenueCat conversion retrieval, local state persistence, funnel diagnostics, and report generation. That subset does fit part of the declared analytics/optimization functionality, but the primary behavior of this chunk is reporting rather than content creation or publishing. There are no undeclared suspicious capabilities beyond the declared analytics integrations; however, there is a material description-to-behavior mismatch because many headline capabilities in the description are not represented in the code and the actual primary purpose is narrower than advertised.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The supplied code chunk implements only one narrow component of the described system: generating six raw slideshow images from prompts via selectable image-generation providers. Its external interactions are limited to image-generation APIs and local filesystem I/O. The declared description presents an end-to-end TikTok marketing automation workflow with research, creative assembly, posting, analytics, and optimization. None of those broader capabilities appear in this code chunk. While image generation is one subset of the declaration, the primary purpose of this specific code is materially narrower than the declared purpose, so the description does not accurately represent what this code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description promises an end-to-end TikTok marketing automation workflow with competitor research, creative generation, social posting, analytics, and feedback-loop optimization. The supplied code only implements an onboarding helper script: it creates directories and template JSON files, validates presence of required config fields, and prints a setup summary. There are no browser actions, no image generation calls, no Postiz/TikTok API requests, no analytics retrieval, and no optimization logic. While the file structure references concepts like competitors, hooks, cross-posting, and RevenueCat, these are placeholders/config fields rather than implemented capabilities. Therefore the description materially overstates the code’s actual behavior and primary purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a broad end-to-end TikTok marketing automation capability with research, content generation, multi-platform posting, analytics, and optimization. The supplied code only performs one narrow function: it reads six PNG files from a local directory, uploads them to Postiz, creates a TikTok slideshow post (defaulting to draft/privacy SELF_ONLY), and writes simple metadata to a local meta.json file. There is no evidence of browser-based competitor research, AI image creation, text overlay processing, analytics ingestion, conversion tracking, or iterative optimization logic. This is a material description-behavior mismatch because the actual code implements only a small posting subset of the declared system.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs storing API keys and secret credentials in configuration without a strong safety warning or safer storage pattern. Plain inclusion of secrets in config files increases the risk of accidental commit, local disclosure, backup leakage, or downstream prompt/tool exposure.

Content

No source excerpt is available for this finding.

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
85% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · SKILL.md (reported line 195)May include surrounding context.

md
**Save the agreed prompt style to config as `imageGen.basePrompt`** so every future post uses it.

**Key prompt rules (explain these as they come up, don't lecture):**
- "iPhone photo" + "realistic lighting" = looks real, not AI-generated
- Lock architecture/layout in EVERY slide prompt or each slide looks like a different place
- Include everyday objects (mugs, remotes, magazines) for lived-in feel

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 323)May include surrounding context.

md
Task: Run scripts/daily-report.js --config tiktok-marketing/config.json --days 3

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 686)May include surrounding context.

md
Task: Run scripts/daily-report.js --config tiktok-marketing/config.json --days 3

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The sample config stores highly sensitive secrets in plaintext, including OpenAI, Postiz, and RevenueCat keys. In skill ecosystems, config files are often shared, synced, backed up, or committed, so plaintext secret storage creates a direct path to credential theft and account compromise.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 409)May include surrounding context.

md
Use `scripts/generate-slides.js`:

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 412)May include surrounding context.

md
Use `scripts/generate-slides.js`:

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 628)May include surrounding context.

md
Use `scripts/check-analytics.js` to automate the connection:

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 631)May include surrounding context.

md
Use `scripts/check-analytics.js` to automate the connection:

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill clearly directs network-capable actions such as browser-based competitor research, API use with Postiz/OpenAI/RevenueCat, and analytics retrieval, but it does not declare corresponding tool scope or permissions. That mismatch weakens user transparency and policy enforcement, making it easier for an agent to perform external actions the user did not explicitly expect.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The invocation text is broad enough to trigger on many generic marketing discussions, which raises the chance that the skill activates in contexts where the user did not intend browser access, posting, analytics, or system setup. Over-broad auto-invocation is dangerous for a skill with external integrations and system-modifying guidance.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill tells the agent to verify and install Node.js and native dependencies on the user's system, expanding from marketing workflow guidance into system modification. That increases the blast radius significantly because package installation can alter the host environment, pull untrusted code, and require elevated privileges.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill directs installation of another skill and additional software components, creating a transitive trust problem where one skill causes the agent to fetch and enable more code. This can unintentionally broaden permissions and introduce supply-chain risk beyond the original user request.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs creation of a persistent daily cron job that continues to run and message the user after setup. Persistent automation is sensitive because it changes system state and can cause repeated network/API actions and data processing without fresh user approval each time.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The cron/reporting workflow includes ongoing report generation and automated user messaging, but the file does not foreground that as a persistent behavior requiring strong consent. Users may not realize they are enabling recurring background actions and notifications.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

OS-level package manager commands for Homebrew, apt, and npm instruct the agent to modify the local machine well beyond content creation logic. In a skill context, embedding such commands can normalize broad host changes and create avoidable risk from dependency installation and privilege escalation.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
88% confidence
Finding

Including sudo-based package installation encourages elevated execution on the user's machine for a non-admin core task. Running package manager commands with root privileges increases the impact of mistakes, malicious package compromise, or command misuse.

Content

Scanner excerpt · SKILL.md (reported line 452)May include surrounding context.

md
>
> **Ubuntu/Debian:**
> ```bash
> sudo apt-get install build-essential libcairo2-dev libpango1.0-dev libjpeg-dev libgif-dev librsvg2-dev
> npm install canvas
> ```
>

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The markdown instructs setting up a recurring cron job that fetches external data, generates reports, updates local files, and messages the user, but it does not warn about persistent scheduled execution or repeated filesystem modification. In an agent skill context, unattended recurring actions increase risk because they can continue exfiltrating metadata, consuming API quotas, and altering local state without fresh user awareness.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/check-analytics.js:47