Back to skill

Security audit

SocQ Facebook Marketplace Research

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed SocQ integration for researching public Facebook Marketplace data, with expected external API use and no hidden persistence or destructive behavior found.

Install only if you intend to use SocQ for public Facebook Marketplace research and are comfortable providing a SOCQ_API_KEY to SocQ tooling. Prefer a preinstalled or pinned socq CLI over runtime npx, review expected credit cost before larger jobs, and clear any local SocQ login when it is no longer needed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding
The skill permits invoking tooling through `npx` without pinning an exact package version, which creates a supply-chain risk: a future compromised or unexpected package release could be fetched and executed at runtime. In an agent skill context, this is more dangerous because the agent may automatically follow the fallback path and run remote code with access to environment variables such as `SOCQ_API_KEY`.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding
The instruction to use `npx @socq/cli` fetches and executes the latest published package unless a version is pinned, exposing users to dependency confusion or malicious upstream updates. Because this skill is explicitly designed to authenticate to a third-party service and handle API keys, compromise of the fetched CLI could lead to credential theft or unauthorized requests.

External Transmission

Medium
Category
Data Exfiltration
Content
value: "socq"
      description: "Hosted SocQ Facebook Marketplace data tools"
      transport: "streamable_http"
      url: "https://api.socq.ai/mcp?platforms=facebook-marketplace"
Confidence
50% confidence
Finding
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

External Transmission

Medium
Category
Data Exfiltration
Content
value: "socq"
      description: "Hosted SocQ Facebook Marketplace data tools"
      transport: "streamable_http"
      url: "https://api.socq.ai/mcp?platforms=facebook-marketplace"
Confidence
50% confidence
Finding
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:32