T08 · Insecure Dependencies
- Location
README.md:27- Finding
Unpinned Package Execution During Installation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill clearly targets social posting, but it gives an agent live publish, edit, and cancel authority over connected accounts without enough confirmation guidance.
Install only if you are comfortable giving the agent an Upload-Post API key that can publish to connected social accounts. Before using it, require the agent to show the exact profile, platforms, content, schedule time, and job_id details before any publish, retry, edit, or cancel action, and avoid the unpinned npx install path in sensitive environments.
README.md:27Unpinned Package Execution During Installation
The skill exposes destructive parameterized operations, including DELETE and PATCH on scheduled posts by job_id, without emphasizing confirmation or guardrails around target selection. In an agent workflow, a malformed, attacker-influenced, or misbound job_id could cancel or alter the wrong scheduled content on connected accounts, causing unauthorized business-impacting changes.
Response includes `job_id`. Manage with:
- `GET /uploadposts/schedule` - List all scheduled
- `DELETE /uploadposts/schedule/<job_id>` - Cancel
- `PATCH /uploadposts/schedule/<job_id>` - Edit (date, title, caption)
## Check Upload Status
The README explicitly promotes uploading and cross-posting content to many external social platforms, but it does not warn users that agent-triggered actions will transmit content off-host and may publish to real accounts. In an agent skill context, this omission is dangerous because users may authorize or invoke the skill without understanding that it can cause irreversible account-impacting actions across multiple services.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
## Setup
1. Create account at [upload-post.com](https://upload-post.com)
2. Connect your social media accounts
3. Create a **Profile** (links your connected accounts)
4. Generate an **API Key** from dashboard
The setup instructions tell users to expose an API key directly to the agent environment without emphasizing that the credential grants posting access to linked social accounts and must be treated as sensitive. In an LLM/agent environment, credential exposure is especially risky because prompts, logs, tool output, and other skills may accidentally disclose or misuse the key.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Upload a video
curl -X POST "https://api.upload-post.com/api/upload" \
-H "Authorization: Apikey YOUR_KEY" \
-F "user=profile_name" \
-F "platform[]=instagram" \
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Upload a video
curl -X POST "https://api.upload-post.com/api/upload" \
-H "Authorization: Apikey YOUR_KEY" \
-F "user=profile_name" \
-F "platform[]=instagram" \
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Upload a video
curl -X POST "https://api.upload-post.com/api/upload" \
-H "Authorization: Apikey YOUR_KEY" \
-F "user=profile_name" \
-F "platform[]=instagram" \
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Upload a video
curl -X POST "https://api.upload-post.com/api/upload" \
-H "Authorization: Apikey YOUR_KEY" \
-F "user=profile_name" \
-F "platform[]=instagram" \
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Upload a video
curl -X POST "https://api.upload-post.com/api/upload" \
-H "Authorization: Apikey YOUR_KEY" \
-F "user=profile_name" \
-F "platform[]=instagram" \
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Upload a video
curl -X POST "https://api.upload-post.com/api/upload" \
-H "Authorization: Apikey YOUR_KEY" \
-F "user=profile_name" \
-F "platform[]=instagram" \
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Upload a video
curl -X POST "https://api.upload-post.com/api/upload" \
-H "Authorization: Apikey YOUR_KEY" \
-F "user=profile_name" \
-F "platform[]=instagram" \
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Upload a video
curl -X POST "https://api.upload-post.com/api/upload" \
-H "Authorization: Apikey YOUR_KEY" \
-F "user=profile_name" \
-F "platform[]=instagram" \
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Upload a video
curl -X POST "https://api.upload-post.com/api/upload" \
-H "Authorization: Apikey YOUR_KEY" \
-F "user=profile_name" \
-F "platform[]=instagram" \
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Upload a video
curl -X POST "https://api.upload-post.com/api/upload" \
-H "Authorization: Apikey YOUR_KEY" \
-F "user=profile_name" \
-F "platform[]=instagram" \
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Upload a video
curl -X POST "https://api.upload-post.com/api/upload" \
-H "Authorization: Apikey YOUR_KEY" \
-F "user=profile_name" \
-F "platform[]=instagram" \
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Upload a video
curl -X POST "https://api.upload-post.com/api/upload" \
-H "Authorization: Apikey YOUR_KEY" \
-F "user=profile_name" \
-F "platform[]=instagram" \
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Upload a video
curl -X POST "https://api.upload-post.com/api/upload" \
-H "Authorization: Apikey YOUR_KEY" \
-F "user=profile_name" \
-F "platform[]=instagram" \
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Upload a video
curl -X POST "https://api.upload-post.com/api/upload" \
-H "Authorization: Apikey YOUR_KEY" \
-F "user=profile_name" \
-F "platform[]=instagram" \
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Upload a video
curl -X POST "https://api.upload-post.com/api/upload" \
-H "Authorization: Apikey YOUR_KEY" \
-F "user=profile_name" \
-F "platform[]=instagram" \
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Upload a video
curl -X POST "https://api.upload-post.com/api/upload" \
-H "Authorization: Apikey YOUR_KEY" \
-F "user=profile_name" \
-F "platform[]=instagram" \
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Upload a video
curl -X POST "https://api.upload-post.com/api/upload" \
-H "Authorization: Apikey YOUR_KEY" \
-F "user=profile_name" \
-F "platform[]=instagram" \
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Upload a video
curl -X POST "https://api.upload-post.com/api/upload" \
-H "Authorization: Apikey YOUR_KEY" \
-F "user=profile_name" \
-F "platform[]=instagram" \
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Upload a video
curl -X POST "https://api.upload-post.com/api/upload" \
-H "Authorization: Apikey YOUR_KEY" \
-F "user=profile_name" \
-F "platform[]=instagram" \
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Upload a video
curl -X POST "https://api.upload-post.com/api/upload" \
-H "Authorization: Apikey YOUR_KEY" \
-F "user=profile_name" \
-F "platform[]=instagram" \
No suspicious patterns detected.