Back to skill

Security audit

PostLake publish

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward PostLake helper for immediately publishing user-selected social media posts, with the main risk being accidental live posting if users do not confirm targets and content first.

Install only if you intend agents to publish directly to connected PostLake social accounts. Before use, confirm the exact text, media, profile or account IDs, platforms, and whether the selected profile expands to multiple live accounts.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
This skill performs an irreversible real-world action by immediately publishing content to live social media accounts, but the description does not prominently warn the user about that consequence. In an agent setting, weak disclosure increases the risk of accidental posting, confused consent, or misuse where a user intended drafting or scheduling rather than immediate publication.

VirusTotal

58/58 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.