Back to skill

Security audit

AI Detector & Humanizer for LinkedIn/X Posts

Security checks for vulnerabilities and agentic risk

Overview

This is a simple social-post review skill that visibly sends draft text to SocialNexis for analysis, with no installer, persistence, credential use, or hidden local access.

Install only if you are comfortable sending social post drafts to SocialNexis for analysis. Avoid using it with confidential business plans, personal data, regulated content, or unpublished sensitive copy unless you have reviewed SocialNexis's privacy and retention practices.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs the agent to send the user's draft text to external SocialNexis HTTP endpoints, but it does not explicitly warn that user content will leave the local system. If users provide confidential drafts, internal messaging, or sensitive personal data, the agent could exfiltrate that content to a third-party service without informed consent.

Static analysis

No suspicious patterns detected.