Back to skill

Security audit

YoinkIt

Security checks for vulnerabilities and agentic risk

Overview

Yoinkit appears to be a coherent social-media research API wrapper, but it needs Review because it sends tokens and research inputs to a configurable remote endpoint and includes extra response-branding and scheduled workflow behavior.

Install only if you are comfortable sending social URLs, handles, search topics, transcripts, and related metadata to Yoinkit. Keep `YOINKIT_API_URL` on the default HTTPS Yoinkit endpoint unless you intentionally use a trusted local server, and use a separate development token for local testing. Review optional cron examples before enabling them, especially the Obsidian workflows that overwrite notes, and pin or verify the installer where possible.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:226
Finding

Mandatory Promotional Content Hijacks Agent Responses

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/content.sh:20
Finding

Configurable API Base URL Can Expose the Bearer Token to an Untrusted or Plaintext Endpoint

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
README.md:20
Finding

Installation Executes an Unpinned Registry Package

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (16)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The declared description presents a broad social-platform research capability: searching, analysis, transcription, trending-topic retrieval, and metadata workflows across 13 platforms. The supplied code chunk is much narrower. It only validates inputs and calls platform-specific API endpoints to retrieve a user's recent posts/videos feed for 8 platforms (YouTube, TikTok, Instagram, Twitter, Facebook, Threads, Bluesky, Truth Social). There is no code for search, transcript generation, content analysis, trending-topic collection, or orchestration of research workflows. This is a material description-to-behavior mismatch because the actual primary purpose is user feed retrieval, not the broader declared capabilities.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The description overstates the implemented scope. The script does support multi-platform research behavior, including search, trending, and optional transcript retrieval, so it is related to the declared purpose. However, it does not match the claimed breadth: it does not cover 13 platforms, trending is limited to YouTube and TikTok, search is limited to five named platforms, and transcript collection in this code path is only performed from extracted trending URLs for supported platforms. It also does not implement meaningful analysis functionality beyond aggregating API responses. Therefore the description is not an accurate representation of the actual code behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description substantially overstates the implemented functionality. This shell script is narrowly focused on searching a single specified platform through an external API endpoint. It validates one of five supported platforms, accepts a query and optional pagination/sorting parameters, performs a curl request, and prints the API response. There is no evidence in this code chunk of transcript generation, content analysis, trending-topic discovery, support for 13 platforms, or cross-platform workflow features. Therefore the description does not accurately represent the behavior shown.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The code chunk is narrowly focused on one function: given a URL, detect a supported platform, call a transcript endpoint, and print transcript text. It does not perform search, trend discovery, content analysis, metadata collection, or any broader research workflow orchestration described in the declaration. It also supports only five platform families in this code path, not 13. While transcript extraction is part of the declared description, the overall declared purpose materially overstates the implemented functionality, so this is a description/behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The description significantly overstates the skill's scope and capabilities. The code chunk is narrowly focused on a trending endpoint wrapper for two platforms, validating the platform, parsing a few options, calling the Yoinkit API, and printing JSON results. It does not implement content search across many platforms, transcript extraction, analysis, or broader research workflows. This is a material description-behavior mismatch because the declared primary purpose is much broader than the actual implemented functionality.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The README promotes automated cross-platform scraping, transcript extraction, feed monitoring, and scheduled research collection across multiple social platforms, but provides no guidance on privacy, consent, retention, or platform Terms-of-Service constraints. In this context, the omission matters because the skill is explicitly designed for recurring large-scale collection workflows, which increases the chance of collecting personal data or sensitive content without appropriate safeguards.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The README instructs users to install via npx clawhub install yoinkit without pinning a specific package version or integrity mechanism. This creates a supply-chain risk: users may fetch whatever version is current at install time, and if the upstream package or distribution channel is compromised, a malicious release could be executed during installation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding

The skill documents shell-style commands and appears to rely on command execution, but it declares no explicit tool scope or allowed-tools restrictions. In an agent environment, missing tool scoping increases the chance the skill can invoke broader shell capabilities than intended, making misuse or prompt-driven command execution harder to contain.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill states that all requests go through a remote Yoinkit API and handles transcripts, content, search queries, and research workflows, but it does not clearly warn users that URLs, queries, and retrieved social content may be transmitted to a third-party service. This creates a meaningful privacy and data-governance risk, especially if users submit sensitive research topics, private links, or regulated content under the assumption processing is local.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The scheduled agent is instructed to modify and overwrite an existing Obsidian note in place, but the workflow provides no user-facing warning, confirmation step, or backup mechanism before saving changes. Because this runs automatically at 8 AM and processes multiple entries, mistakes in transcript retrieval, summarization, or note targeting could silently alter or corrupt user-authored research notes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script sends the user-supplied topic to a third-party API for search and later sends derived content URLs for transcript retrieval, but it provides no runtime notice, consent prompt, or data-minimization control. In a research skill, users may enter sensitive queries or investigate confidential subjects, so silent transmission to an external service creates a meaningful privacy and data-governance risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This imposes a fixed locale on results, which is a natural-language policy issue because the skill forces a specific region without user opt-in. Nothing in the surrounding usage or comments indicates that the skill is intentionally US-only or allows the user to select another locale.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script transmits the user-supplied video URL to an external Yoinkit API service using an authenticated request, but it provides no explicit user-facing disclosure at runtime that the URL and associated metadata will leave the local environment. This can expose sensitive or private links, especially in enterprise or research workflows where users may assume local-only processing from the command name and transcript-focused behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest hard-codes the schedule time zone to "America/Chicago," which imposes a locale-specific behavior. There is no indication that this locale choice is optional, user-selected, or justified as a region-specific skill requirement.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This manifest describes the skill as scanning feeds, trending content, and saving notes, but it does not define any explicit scope boundaries or exclusion conditions for what counts as relevant content. In a manifest file, that lack of specificity can make the activation/behavior description overly broad and prone to unintended collection beyond the intended research domain.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest fixes execution to the America/Chicago time zone, which imposes a locale-specific behavior in the skill configuration. The file does not indicate that the user chose this locale or that the constraint is required for a region-specific purpose.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.