Back to skill

Security audit

PostLake schedule

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward PostLake scheduling helper, with disclosed API-key use and expected schedule, edit, list, and cancel operations.

Install only if you intend to let the agent manage your PostLake scheduled posts. Because the skill can create, edit, and cancel public social content using your API key, ask the agent to summarize the target post, account, and scheduled time before any edit or cancellation.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill documents a destructive DELETE operation for canceling scheduled posts but provides no requirement to confirm user intent before executing it. In an agent setting, ambiguous requests, mis-clicks, or prompt manipulation could cause unintended cancellation of queued content, leading to business disruption or loss of planned communications.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.