Back to skill

Security audit

facebook-data

Security checks for vulnerabilities and agentic risk

Overview

This skill wraps a third-party Facebook data API but exposes people, seller, marketplace, and ad-research endpoints beyond its narrow short description, so it needs review before use.

Install only if you intend to use Superagnt as a third-party provider for Facebook-derived research data. Review whether your use of people search, seller details, group content, comments, marketplace listings, and ad data complies with applicable privacy rules, platform terms, and consent expectations; prefer explicit user approval before invoking people or seller endpoints.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest description narrows the skill to pages, posts, and group data, but the body documents broader capabilities including marketplace listings, seller details, ad discovery, and people search. This mismatch can mislead users and policy systems about the actual scope of data access, increasing the chance of unintended collection or approval of higher-risk operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill facilitates remote collection of Facebook people, group, seller, ad, and marketplace data but does not disclose privacy, consent, or data-use constraints. In practice this makes sensitive data collection easier to normalize and increases the likelihood of misuse or policy noncompliance by downstream agents.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 64)May include surrounding context.

One call proves the key, the credit balance, and this source end to end:

bash
curl -s https://api.superagnt.com/v1/credits \
  -H 'Authorization: Bearer $SUPERAGNT_API_KEY'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 74)May include surrounding context.

One call proves the key, the credit balance, and this source end to end:

bash
curl -s https://api.superagnt.com/v1/credits \
  -H 'Authorization: Bearer $SUPERAGNT_API_KEY'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 1075)May include surrounding context.

One call proves the key, the credit balance, and this source end to end:

bash
curl -s https://api.superagnt.com/v1/credits \
  -H 'Authorization: Bearer $SUPERAGNT_API_KEY'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 1094)May include surrounding context.

One call proves the key, the credit balance, and this source end to end:

bash
curl -s https://api.superagnt.com/v1/credits \
  -H 'Authorization: Bearer $SUPERAGNT_API_KEY'

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

People search is materially more privacy-sensitive than page/post/group research and is not clearly justified by the stated business purpose. In an agent setting, this can enable profiling or collection of personal data under the guise of brand research, creating misuse and compliance risk.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation states authentication uses an Authorization Bearer token, but the example later uses X-API-Key. Inconsistent auth guidance can cause integration errors, accidental key exposure through ad hoc troubleshooting, or clients sending secrets in unintended formats.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.