Threads Publisher
v1.0.1Publish posts and threads to Threads (by Meta). Use when the user says 'post to Threads', 'create a thread', 'publish thread', 'write a Threads post', 'reply...
⭐ 1· 117·1 current·1 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Benign
medium confidencePurpose & Capability
The skill claims to publish posts/threads to Threads and requires a single MCP Connector link that contains an embedded auth token granting publish access. That credential is directly relevant and expected for a third‑party publishing bridge.
Instruction Scope
Instructions are limited to listing accounts, uploading media, publishing posts/threads, and scheduling. They reference uploading local files (file_path) and passing Google Drive URLs; those are appropriate for a publisher but mean the agent may need user-provided files/links. The SKILL.md does not instruct reading unrelated local system files or environment variables.
Install Mechanism
This is an instruction-only skill with no install spec and no code files, so nothing is written to disk or downloaded by the skill itself.
Credentials
No local environment variables are requested. The single required artifact is an MCP Connector URL with an embedded token; it is proportionate to a publishing tool but is a high-privilege credential (can create posts, upload media, schedule posts across connected accounts). Treat it as sensitive.
Persistence & Privilege
The skill does not request always:true and does not declare any behavior that modifies other skills or system-wide settings. Autonomous invocation is allowed by default but is not combined with additional red flags here.
Assessment
This skill appears coherent for its purpose, but before installing: (1) only paste the MCP Connector link if you trust boring.aiagent-me.com — the link embeds a token that can publish to any connected accounts; treat it like a password and revoke/regenerate if compromised; (2) understand that providing local files or Drive links will allow the agent to read those assets to attach to posts; (3) verify the third‑party service (boring.aiagent-me.com / the GitHub repo) and its privacy/security practices before granting publish access; (4) prefer creating a minimally privileged connector or limiting which accounts are connected where possible; and (5) if you need higher assurance, test with an unprivileged or disposable account first.Like a lobster shell, security has layers — review code before you run it.
latestvk9734zk8mwgdar7p1cvm8th59183qpm6
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
Runtime requirements
🧵 Clawdis
ConfigMCP Connector link from boring.aiagent-me.com (contains embedded auth token)
