Back to skill

Security audit

social-week

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed PostWire workflow for planning and scheduling social posts, with explicit user approval required before publishing, scheduling, or canceling.

Install this only if you want an agent to help manage a PostWire social publishing workflow. It can use your PostWire account, connected social networks, uploaded media links, and performance data, so review generated posts carefully and only approve scheduling or cancellation when the exact text, networks, dates, times, and timezone are correct.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (9)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

md
description: Only to test scripts/schedule-week.mjs against another server. Default https://postwire.io.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 231)May include surrounding context.

md
description: Only to test scripts/schedule-week.mjs against another server. Default https://postwire.io.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 233)May include surrounding context.

md
description: Only to test scripts/schedule-week.mjs against another server. Default https://postwire.io.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 173)May include surrounding context.

md
The dry run answers per row: the time it will go out, each network's length as that network counts it, X credits,
   whether it waits for approval, whether the plan holds it, and errors. Fix the errors, show anything that changed,
   then send the same rows with `dry_run: false`. It schedules every row or none. Keep the `batch_id`: the whole week
   can be undone with `DELETE /api/bulk/{batch_id}`, or one post with `cancel_scheduled_post`.
   Without `bulk_schedule`, call `schedule_post` once per row (`run_at` with an offset or `"next_slot"`,
   `per_platform`, `label`).
5. Results to respect, never to retry around:

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 247)May include surrounding context.

md
| Account, plan, connections | `GET /api/me` |
| Link to connect networks | `POST /api/connect-link` `{ "platform"? , "brand_id"? }` |
| Check, then schedule the week | `POST /api/bulk` `{ "rows": […], "timezone": "…", "dry_run": true }`, then `false` |
| Undo the week | `DELETE /api/bulk/{batch_id}` |
| One post | `POST /api/schedule` `{ "platforms", "per_platform", "run_at", "label" }` |
| Next free slot | `GET /api/schedule/next-slot?platforms=linkedin,bluesky&timezone=…` |
| The queue | `GET /api/schedule?from=…&to=…` |

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill explicitly instructs the agent to read environment variables and make authenticated network requests, but it does not declare a restrictive tool scope such as allowed tools, domains, or permissions. That increases the chance an agent runtime will grant broader-than-necessary access, making misuse of secrets or unintended outbound requests more likely if the skill is invoked in the wrong context.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description contains very broad trigger phrases such as 'what to post this week' and 'to fill or schedule their social queue,' which can overlap with common marketing requests. In agents that auto-select skills from descriptions, this can cause over-invocation of a network-capable skill and lead to unnecessary account checks, outbound requests, or scheduling workflows being proposed in contexts where the user only wanted advice.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 12)May include surrounding context.

md
updated: "2026-10-06"
  author: PostWire
  homepage: https://postwire.io/skills/social-week/
  canonical: https://postwire.io/skills/social-week/SKILL.md
  openclaw:
    homepage: https://postwire.io/skills/social-week/
    primaryEnv: POSTWIRE_API_KEY

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 267)May include surrounding context.

md
updated: "2026-10-06"
  author: PostWire
  homepage: https://postwire.io/skills/social-week/
  canonical: https://postwire.io/skills/social-week/SKILL.md
  openclaw:
    homepage: https://postwire.io/skills/social-week/
    primaryEnv: POSTWIRE_API_KEY

Static analysis

No suspicious patterns detected.