Back to skill

Security audit

breakreach

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for managing Breakreach social media accounts, but it should be reviewed because it recommends unpinned CLI execution that can handle API keys, local media files, and public posting actions.

Install only if you trust Breakreach with the connected social accounts, private messages, comments, analytics, and media you ask it to handle. Prefer the hosted MCP or a pinned, vetted CLI version over floating `npx breakreach`, especially in CI or when using API keys and local files. Review public posts, DMs, comment moderation, and delete actions carefully before allowing the agent to run them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (30)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/rest-and-cli.md (reported line 52)May include surrounding context.

md
| `GET /v1/accounts` | `list_accounts` |
| `POST /v1/connect-links` | `create_connect_link` |
| `POST /v1/posts`, `GET /v1/posts?status=` | `create_post`, `list_posts` |
| `PATCH /v1/posts/{id}`, `DELETE /v1/posts/{id}` | `update_post`, `delete_post` |
| `POST /v1/media` (`{url}`), `POST /v1/media/upload` (multipart `file`) | `upload_media` (URL only) |
| `GET /v1/next-slot`, `GET /v1/pinterest-boards` | `get_next_slot`, `list_pinterest_boards` |
| `GET /v1/posts/{id}/metrics`, `GET /v1/performance`, `GET /v1/post-insights` | `get_post_metrics`, `get_content_performance`, `get_post_insights` |

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description is very broad and encourages activation for posting, scheduling, reading comments/DMs, answering messages, and viewing analytics across many platforms. In an agent setting, such broad trigger language can cause over-invocation and unintended high-impact actions on external accounts without sufficiently narrow user confirmation boundaries.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill exposes access to comments, direct messages, and analytics but does not prominently warn that these are privacy-sensitive and may involve personal or confidential data. In practice, this can lead to silent retrieval or processing of private communications under broad user requests, increasing privacy and compliance risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

Again, the issue is unpinned package execution via npx breakreach on line 19. In agent environments this is especially relevant because the command may be run automatically, pulling and executing changing third-party code that can access credentials or the filesystem.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill tells users to upload local files with npx breakreach upload <file> without pinning a version. That creates a direct supply-chain execution path in a sensitive context because the invoked tool handles local files and may have access to secrets and content being uploaded.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The terminal/CI examples use npx breakreach post ... without a pinned version. CI environments are high-value targets for supply-chain compromise because they often expose tokens and can perform privileged publishing actions automatically.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 18)May include surrounding context.

md
# Breakreach without MCP: CLI, REST, SDKs

Everything the MCP tools do is also a REST endpoint under `https://api.breakreach.com/v1`, with an API key (Breakreach, Settings → API & MCP, `br_...`). The rules of SKILL.md are the same: account ids from the accounts call, `scheduledAt` in the workspace timezone, media as public URLs.

## CLI

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 24)May include surrounding context.

md
# Breakreach without MCP: CLI, REST, SDKs

Everything the MCP tools do is also a REST endpoint under `https://api.breakreach.com/v1`, with an API key (Breakreach, Settings → API & MCP, `br_...`). The rules of SKILL.md are the same: account ids from the accounts call, `scheduledAt` in the workspace timezone, media as public URLs.

## CLI

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 25)May include surrounding context.

md
# Breakreach without MCP: CLI, REST, SDKs

Everything the MCP tools do is also a REST endpoint under `https://api.breakreach.com/v1`, with an API key (Breakreach, Settings → API & MCP, `br_...`). The rules of SKILL.md are the same: account ids from the accounts call, `scheduledAt` in the workspace timezone, media as public URLs.

## CLI

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

md
# Breakreach without MCP: CLI, REST, SDKs

Everything the MCP tools do is also a REST endpoint under `https://api.breakreach.com/v1`, with an API key (Breakreach, Settings → API & MCP, `br_...`). The rules of SKILL.md are the same: account ids from the accounts call, `scheduledAt` in the workspace timezone, media as public URLs.

## CLI

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 122)May include surrounding context.

md
# Breakreach without MCP: CLI, REST, SDKs

Everything the MCP tools do is also a REST endpoint under `https://api.breakreach.com/v1`, with an API key (Breakreach, Settings → API & MCP, `br_...`). The rules of SKILL.md are the same: account ids from the accounts call, `scheduledAt` in the workspace timezone, media as public URLs.

## CLI

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/rest-and-cli.md (reported line 3)May include surrounding context.

md
# Breakreach without MCP: CLI, REST, SDKs

Everything the MCP tools do is also a REST endpoint under `https://api.breakreach.com/v1`, with an API key (Breakreach, Settings → API & MCP, `br_...`). The rules of SKILL.md are the same: account ids from the accounts call, `scheduledAt` in the workspace timezone, media as public URLs.

## CLI

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/rest-and-cli.md (reported line 35)May include surrounding context.

md
# Breakreach without MCP: CLI, REST, SDKs

Everything the MCP tools do is also a REST endpoint under `https://api.breakreach.com/v1`, with an API key (Breakreach, Settings → API & MCP, `br_...`). The rules of SKILL.md are the same: account ids from the accounts call, `scheduledAt` in the workspace timezone, media as public URLs.

## CLI

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/rest-and-cli.md (reported line 37)May include surrounding context.

md
# Breakreach without MCP: CLI, REST, SDKs

Everything the MCP tools do is also a REST endpoint under `https://api.breakreach.com/v1`, with an API key (Breakreach, Settings → API & MCP, `br_...`). The rules of SKILL.md are the same: account ids from the accounts call, `scheduledAt` in the workspace timezone, media as public URLs.

## CLI

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/rest-and-cli.md (reported line 41)May include surrounding context.

md
# Breakreach without MCP: CLI, REST, SDKs

Everything the MCP tools do is also a REST endpoint under `https://api.breakreach.com/v1`, with an API key (Breakreach, Settings → API & MCP, `br_...`). The rules of SKILL.md are the same: account ids from the accounts call, `scheduledAt` in the workspace timezone, media as public URLs.

## CLI

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/rest-and-cli.md (reported line 61)May include surrounding context.

md
# Breakreach without MCP: CLI, REST, SDKs

Everything the MCP tools do is also a REST endpoint under `https://api.breakreach.com/v1`, with an API key (Breakreach, Settings → API & MCP, `br_...`). The rules of SKILL.md are the same: account ids from the accounts call, `scheduledAt` in the workspace timezone, media as public URLs.

## CLI

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The documentation instructs users to execute npx breakreach without pinning a specific package version. This allows whatever version is currently published under that package name to be fetched and executed at runtime, creating a supply-chain risk if the package is compromised, maliciously republished, or changed incompatibly.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The second unpinned npx breakreach invocation on this line has the same supply-chain exposure: it executes whichever package version is current at invocation time. Because the command reads an API key from stdin, a compromised package could directly exfiltrate that credential.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The whoami example relies on an unpinned npx execution path, introducing a dependency on the latest published package version. Even read-oriented commands can expose workspace metadata and cached credentials if the fetched package is malicious.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

This unpinned CLI example inherits the same package substitution and compromised-release risk as the other npx commands. Since it enumerates accounts, a malicious package could harvest account identifiers and environment details useful for follow-on abuse.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

This command can publish content across multiple social networks, yet it is invoked through an unpinned npx package. A compromised or altered package could silently modify post content, targets, or exfiltrate credentials before submitting requests.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

This --now posting example executes an unpinned CLI package that can immediately perform side effects on connected social accounts. In this context, supply-chain compromise is more dangerous because the tool has direct authority to publish content externally.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The draft-post example still executes an unpinned package from the registry, exposing users to arbitrary code execution risk from the fetched CLI. Even if the operation is non-final, the tool still handles authenticated workspace context and post content.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

Reading post content from stdin into an unpinned npx command combines supply-chain risk with handling of potentially sensitive unpublished content. A malicious package could capture or alter the input before submission.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The failed-post listing example uses unpinned npx, which can execute arbitrary code from the latest package release. Although the action is read-only from the user's perspective, it may expose account state, post metadata, and stored auth context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.