Back to skill

Security audit

营销引流工具包

Security checks for vulnerabilities and agentic risk

Overview

This skill is transparent about marketing automation, but it directs unattended posting to real social media accounts without clear per-post approval.

Review this carefully before installing. Use it only with accounts where automated public posting is acceptable, and prefer draft-only or explicit per-post approval. Avoid hourly unattended posting unless you fully accept the risk of reputation damage, platform enforcement, and storing account performance data in local logs.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:114
Finding

Autonomous Social Media Publishing Without Per-Post Authorization

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 8, 114-118, and 177
Vulnerability Type: Unauthorized use of an authenticated browser session
Risk Level: High

Relevant instructions translated into English:

markdown
1. **Fully automated publishing** — The MCP browser automatically executes
   the publishing process and notifies the owner only if it fails.
markdown
When the hourly cron job is triggered:
- Analyze whether there are suitable current trends
- Generate content
- Automatically execute the publishing process
- Success: notify the owner with a brief confirmation
- Failure: notify the owner and provide the complete content
markdown
- **Fully automated publishing**: Automatically execute the publishing
  process whether or not the owner is at the computer; notify the owner
  only if it fails.

Technical Analysis

The Skill directs the agent to use an authenticated MCP browser session to perform an irreversible external action—publishing content to X or Weibo—without obtaining explicit approval immediately before submission. The owner is informed only after the operation succeeds or fails.

This behavior violates least-privilege and human-in-the-loop principles. Permission to access an authenticated browser session does not necessarily imply standing authorization to publish arbitrary generated content. The risk is increased by the hourly cron workflow, which can repeatedly generate and submit posts while the owner is absent.

The instructions are also internally inconsistent with other language suggesting that the owner may choose whether to publish. The unconditional automated-publishing directives can override that safer workflow.

No evidence was found that the Skill can obtain credentials, bypass authentication, take over an account, or access privileges beyond those already available in the browser session. The exposed capability ...[truncated 1545 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace automatic submission with a draft-only workflow for all cron and unattended executions.
  2. Require explicit, per-post confirmation immediately before activating the final publishing control.
  3. Present the platform, authenticated account, complete final content, links, and hashtags in the approval prompt.
  4. Treat approval as single-use and bind it to the exact content shown; require renewed approval after any edit.
  5. Default the MCP workflow to dry-run mode and expose publishing as a separately authorized action.
  6. Remove or rewrite the unconditional automated-publishing directives at lines 8 and 177.
  7. Add rate limits, duplicate detection, daily posting caps, and a global emergency-disable control.
  8. Record the approving user, approved content hash, destination platform, account, timestamp, and publication result in an audit log.
  9. Restrict the browser profile used by the Skill to only the necessary accounts and permissions.
  10. On browser errors, authentication changes, unexpected redirects, or content mismatches, stop safely rather than retrying submission automatically.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly promotes fully automatic posting to X and Weibo, including unattended execution via browser automation, without a prominent consent and risk warning before account actions occur. Because this publishes outbound content under the user's identity, a misfire, prompt injection in trend discovery, or bad content generation could directly harm the user's account reputation, violate platform rules, or trigger enforcement actions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill gives conflicting guidance about cron behavior: it says cron is only a suggestion and the owner can choose whether to publish, but elsewhere instructs hourly triggers to generate content and automatically execute posting. This ambiguity is dangerous because it can cause an agent or operator to interpret the skill as authorizing unattended social-media actions, resulting in unintended account activity and content publication.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill instructs use of platform analytics and user-provided screenshots or data for performance analysis but does not warn about privacy, retention, or handling of account-related metrics. While less severe than autonomous posting, this can still expose sensitive business, audience, or account information if data is over-collected, stored insecurely, or shared in logs such as posts-log.md.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.