Back to skill

Security audit

LinkedIn Post Ideas Generator

Security checks for vulnerabilities and agentic risk

Overview

This skill is a simple content-ideation helper that sends user-provided topics or text to a disclosed SocialNexis API and does not install code or request credentials.

Install only if you are comfortable sending the topic, article excerpt, or notes you provide to SocialNexis for processing. Do not paste secrets, private documents, personal data, or confidential business material unless you are authorized to share it with that service.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs users to paste article text or notes into a remote third-party API, but it does not clearly warn that this content leaves the local agent environment and is transmitted to an external service. This creates a real data exposure risk because users may submit proprietary, confidential, or personal information under the assumption the skill operates locally or with the same trust boundary as the agent.

Static analysis

No suspicious patterns detected.