Back to skill

Security audit

SocQ Threads Research

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent SocQ integration for researching public Threads data, with expected external API use and reasonable guardrails.

Before installing, users should understand that Threads research queries, target URLs/usernames, task metadata, and the SocQ API key are used with SocQ's hosted service and may consume credits. Prefer a preinstalled or pinned SocQ CLI where possible, keep SOCQ_API_KEY in the environment, avoid submitting secrets or regulated data as research inputs, and confirm cost before large collections.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

External Transmission

Medium
Category
Data Exfiltration
Content
## Execution

1. Prefer an already configured SocQ MCP server at `https://api.socq.ai/mcp?platforms=threads`; use the typed tool listed in [platform.md](references/platform.md), or compact `socq_execute` when needed.
2. If MCP is unavailable, use `socq` or `npx @socq/cli`. Use REST only as the final fallback.
3. Read [authentication.md](references/authentication.md), keep `SOCQ_API_KEY` in the environment, and never put it in prompts, URLs, committed files, or retained commands.
4. Read [billing.md](references/billing.md), report the expected cost, and obtain confirmation before a paid large-volume or multi-endpoint run.
Confidence
50% confidence
Finding
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding
The skill instructs use of `npx @socq/cli` without a pinned version, which can cause execution of the latest published package at runtime. That creates a supply-chain risk: a malicious or compromised package release could be pulled and executed automatically in the agent environment.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill is designed to collect and analyze Threads data via a hosted third-party MCP endpoint, but the manifest does not clearly disclose to users that requests and any supplied research parameters are sent to an external SocQ service. This creates a transparency and data-handling risk because agents or users may provide sensitive queries, account identifiers, or operational context without realizing that data leaves the local environment.

External Transmission

Medium
Category
Data Exfiltration
Content
value: "socq"
      description: "Hosted SocQ Threads data tools"
      transport: "streamable_http"
      url: "https://api.socq.ai/mcp?platforms=threads"
Confidence
87% confidence
Finding
The manifest hard-codes an external MCP endpoint, meaning use of the skill inherently transmits user-supplied inputs to a remote service outside the agent's local trust boundary. In this context the behavior appears intentional and necessary for functionality, but it is still security-relevant because it can expose prompts, targets of investigation, and other potentially sensitive metadata to the third party.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:32