Back to skill

Security audit

Kleos CLI

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly coherent for managing Kleos social posts, but it grants broad account/tool authority through an unpinned CLI and generic tool-call interface.

Review before installing. Prefer a pinned, reviewed Kleos CLI version or a preinstalled binary, use least-privilege API keys, avoid running this unattended in CI/cron with broad account scopes, and require explicit user approval for publishing, scheduling, spending, account connections, team changes, or generic `kleos call` operations.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (7)

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The manifest references the CLI in a way that operationally encourages unpinned execution of the MCP client, which is a supply-chain risk when agents autonomously install and run tools. In this context, the tool has broad networked capabilities and access to authentication material, increasing the blast radius of a malicious release.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The skill instructs agents to execute npx -y kleos-cli, which fetches and runs the latest package version at runtime without pinning an exact version or integrity digest. This creates a supply-chain execution risk: a compromised package release, account takeover, or malicious dependency update could immediately result in arbitrary code execution in every environment using the skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description lists activation phrases such as "generate posts for my app", "plan the week of posts", and "how are my posts doing", which are broad natural-language requests that could match ordinary conversation rather than an intentionally invoked skill. The file does not provide exclusion conditions or negative examples to clarify when the skill should not activate.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The documentation again directs use of npx -y kleos-cli without a fixed version, causing runtime retrieval and execution of unreviewed code from the package registry. Because this skill also handles API keys, browser login tokens, uploads, and account actions, compromise of the fetched package could expose credentials and perform unauthorized actions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill advertises a relatively focused purpose, but then exposes a generic kleos call <tool> interface to invoke any MCP tool by name, including functionality outside the declared scope. This is dangerous because agents may be socially engineered into performing sensitive or higher-impact operations that users did not reasonably expect from a social-posting skill.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Including invite_member extends the skill into team-management and account-administration territory, which is unrelated to ordinary content creation and scheduling. If an agent can trigger this capability, an attacker could manipulate the agent into adding unauthorized collaborators or escalating access within the platform.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The manifest-style description includes both English and Portuguese trigger phrases, but does not state how the skill determines which language to use or offer an explicit language/locale preference to the user. This can violate language-choice policy when a skill implicitly imposes or switches language without opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.