Back to skill

Security audit

heyrepli

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent HeyRepli API helper that discloses its external API use and social posting capabilities, with no hidden persistence or deceptive behavior found.

Install only if you are comfortable sending social content, scraped identifiers/URLs, and publishing or scheduling requests to HeyRepli with your API key. Review generated content, platform, account connection, and scheduled time before using publish or schedule operations.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

MCP Config Access

High
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill accesses MCP server configuration files (mcp.json). MCP configs contain server URLs, authentication tokens, and tool definitions — reading them allows the skill to discover and potentially abuse other tool integrations.

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

Use scripts/heyrepli.py (Python 3.8+, stdlib only):

bash
# List all MCP tools
python scripts/heyrepli.py list-tools

# Call any MCP tool (scraping, AI rewrite, publish)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill performs network requests and uses environment-based secrets, but the manifest does not declare any tool scope or allowed-tools constraints. This weakens least-privilege controls and makes it easier for the skill to access sensitive capabilities without explicit review, especially given that it can publish content and scrape external services.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The description uses broad trigger phrases like scraping, generating replies, publishing, scheduling, and checking usage across multiple platforms without narrow activation criteria. This can cause over-invocation on common social-media-related requests, increasing the chance of unnecessary external data transfer or unintended posting actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill supports scraping social media data and publishing or scheduling posts, but it does not clearly warn about privacy implications, external data processing, or account-impacting side effects. In this context, omission of such warnings is risky because the skill can act on third-party content and modify connected social accounts.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
76% confidence
Finding

The skill sends user-provided content and account-linked actions to an external API endpoint. External transmission is expected for this integration, but it is still security-relevant because social content, scraped data, and publishing requests leave the local environment and may include sensitive or private information.

Content

Scanner excerpt · SKILL.md (reported line 25)May include surrounding context.

md
## Two API surfaces

- **MCP endpoint** (13 tools, JSON-RPC): `POST https://api.heyrepli.com/api/v1/mcp`
- **Open REST API** (5 endpoints): `https://api.heyrepli.com/api/v1/open/*`

Prefer the helper script; it handles both and prints JSON.

External Transmission

Medium
Category
Data Exfiltration
Confidence
76% confidence
Finding

The open REST API endpoint indicates additional external transmission paths beyond the MCP endpoint. Because the skill supports broad scraping and posting workflows, these outbound requests increase exposure of user data and account actions to a third-party service if not tightly scoped and disclosed.

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

md
## Two API surfaces

- **MCP endpoint** (13 tools, JSON-RPC): `POST https://api.heyrepli.com/api/v1/mcp`
- **Open REST API** (5 endpoints): `https://api.heyrepli.com/api/v1/open/*`

Prefer the helper script; it handles both and prints JSON.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 60)May include surrounding context.

md
- `scrape_youtube_transcript` works without any YouTube API key (Innertube). `scrape_youtube_video` and `scrape_youtube_search` require a YOUTUBE_API_KEY configured in the user's HeyRepli account.
- Rate limits are per plan; on HTTP 429 respect `Retry-After`, never loop.
- Errors return `{ "ok": false, "error": { "code", "message" } }` — surface `message` to the user verbatim.
- API status check: `GET https://api.heyrepli.com/health` (no auth).

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The API reference exposes publish and schedule capabilities to external social platforms without any explicit warning that these actions cause real-world side effects. In an agent-skill context, that omission increases the risk that an LLM or user may invoke posting actions without clear confirmation, potentially leading to unauthorized, accidental, or reputationally damaging social media posts.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.