Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md description: Only to test scripts/schedule-week.mjs against another server. Default https://postwire.io.
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed PostWire workflow for planning and scheduling social posts, with explicit user approval required before publishing, scheduling, or canceling.
Install this only if you want an agent to help manage a PostWire social publishing workflow. It can use your PostWire account, connected social networks, uploaded media links, and performance data, so review generated posts carefully and only approve scheduling or cancellation when the exact text, networks, dates, times, and timezone are correct.
Referenced artifact was not completely inspected
description: Only to test scripts/schedule-week.mjs against another server. Default https://postwire.io.
Referenced artifact was not completely inspected
description: Only to test scripts/schedule-week.mjs against another server. Default https://postwire.io.
Referenced artifact was not completely inspected
description: Only to test scripts/schedule-week.mjs against another server. Default https://postwire.io.
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
The dry run answers per row: the time it will go out, each network's length as that network counts it, X credits,
whether it waits for approval, whether the plan holds it, and errors. Fix the errors, show anything that changed,
then send the same rows with `dry_run: false`. It schedules every row or none. Keep the `batch_id`: the whole week
can be undone with `DELETE /api/bulk/{batch_id}`, or one post with `cancel_scheduled_post`.
Without `bulk_schedule`, call `schedule_post` once per row (`run_at` with an offset or `"next_slot"`,
`per_platform`, `label`).
5. Results to respect, never to retry around:
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
| Account, plan, connections | `GET /api/me` |
| Link to connect networks | `POST /api/connect-link` `{ "platform"? , "brand_id"? }` |
| Check, then schedule the week | `POST /api/bulk` `{ "rows": […], "timezone": "…", "dry_run": true }`, then `false` |
| Undo the week | `DELETE /api/bulk/{batch_id}` |
| One post | `POST /api/schedule` `{ "platforms", "per_platform", "run_at", "label" }` |
| Next free slot | `GET /api/schedule/next-slot?platforms=linkedin,bluesky&timezone=…` |
| The queue | `GET /api/schedule?from=…&to=…` |
The skill explicitly instructs the agent to read environment variables and make authenticated network requests, but it does not declare a restrictive tool scope such as allowed tools, domains, or permissions. That increases the chance an agent runtime will grant broader-than-necessary access, making misuse of secrets or unintended outbound requests more likely if the skill is invoked in the wrong context.
The description contains very broad trigger phrases such as 'what to post this week' and 'to fill or schedule their social queue,' which can overlap with common marketing requests. In agents that auto-select skills from descriptions, this can cause over-invocation of a network-capable skill and lead to unnecessary account checks, outbound requests, or scheduling workflows being proposed in contexts where the user only wanted advice.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
updated: "2026-10-06"
author: PostWire
homepage: https://postwire.io/skills/social-week/
canonical: https://postwire.io/skills/social-week/SKILL.md
openclaw:
homepage: https://postwire.io/skills/social-week/
primaryEnv: POSTWIRE_API_KEY
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
updated: "2026-10-06"
author: PostWire
homepage: https://postwire.io/skills/social-week/
canonical: https://postwire.io/skills/social-week/SKILL.md
openclaw:
homepage: https://postwire.io/skills/social-week/
primaryEnv: POSTWIRE_API_KEY
No suspicious patterns detected.