Back to skill

Security audit

Social Media Kit

Security checks for vulnerabilities and agentic risk

Overview

The package does not appear malicious, but its skill manifest advertises a social-media generator while the shipped documentation and code are actually a landing-page HTML generator.

Install only after the publisher fixes the manifest/package mismatch or you intentionally want a landing-page HTML generator. Treat JSON configs as trusted input only, review generated HTML before opening or publishing it, and expect generated pages to contact Google Fonts and Unsplash unless modified.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/landing_builder.py:1440
Finding

Persistent HTML and JavaScript Injection Through Unescaped URL Attributes

Content
View full analysis
str: name = config.get("name", "Your Brand") desc = config.get("description", "") tagline = config.get("tagline", "") hero_img = config.get("hero_img") or theme_conf.get("hero_img", "") # ... img_html = f'{html_escape(name)} preview' if hero_img else "" ``` Additional affected HTML attributes are generated as follows: ```python og_image = config.get("hero_img") or theme_conf.get("hero_img", "") url = config.get("url", "https://example.com") ``` ```html ``` ### Technical Analysis The `hero_img` and `url` values can originate from an externally supplied JSON configuration. These values are interpolated directly into double-quoted HTML attributes without HTML attribute escaping or URL validation. Other textual fields use `html_escape()`, but these URL fields bypass that protection. An attacker can include a double quote in `hero_img` to terminate the `src` attribute and append an event handler. For example, a configuration value conceptually equivalent to: ```json { "hero_img": "invalid\" onerror=\"alert(document.domain)" } ``` produces an image element with an attacker-controlled `onerror` handler. Because the generated payload is stored in the output file, the injection executes when that file is subsequently opened or deployed. The Open Graph and Twitter metadata sinks also permit arbitrary attribute or element injection. The directly rendered hero image is the clearest script-execution sink because image error handlers are executable browser events. ...[truncated 1122 chars]
Remediation
View remediation
' if hero_img else "" ) ``` 2. Escape metadata values in the same way: ```python safe_og_image = html_escape(str(og_image), quote=True) safe_url = html_escape(str(url), quote=True) ``` 3. Parse URLs with `urllib.parse.urlparse()` and allow only explicitly supported schemes, preferably `https`. Reject control characters, quotes, and unsupported schemes such as `javascript:`. 4. Consider using a template engine with automatic contextual escaping if third-party dependencies become acceptable. 5. Add regression tests containing double quotes, single quotes, angle brackets, event handlers, and malicious URL schemes in every configuration field rendered into an HTML attribute. 6. Treat configuration files from untrusted sources as unsafe until all output contexts have validation and escaping. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/landing_builder.py:1781
Finding

CSS and HTML Injection Through Unvalidated Color Configuration

Content
View full analysis
{generate_logo_initial(name)}"> ``` ### Technical Analysis `generate_palette()` parses only the character slices needed for an RGB prefix, while the original `seed_hex` is retained as `palette["primary"]`. Consequently, a string can begin with a valid six-digit hexadecimal color and contain malicious trailing syntax. The complete value is subsequently inserted into an inline `` block. An attacker can terminate the CSS declaration and potentially inject a literal `` sequence followed by arbitrary HTML. HTML parsing rules recognize the closing style tag even when the sequence appears to be CSS text. The value is also inserted without escaping into the SVG favicon data URL. Quotes and markup delimiters can therefore cross the intended SVG and HTML attribute boundaries. ### Attack Path 1. An attacker supplies a JSON configuration containing a `color` value with ...[truncated 989 chars]
Remediation
View remediation
str: value = str(value).strip() if not re.fullmatch(r"#[0-9A-Fa-f]{6}", value): raise ValueError("Color must use the format #RRGGBB") return value.lower() ``` 2. If three-digit colors are supported, expand them to six digits before storing or rendering them. Do not preserve arbitrary trailing input. 3. Use only the normalized value in `generate_palette()`, CSS declarations, and SVG generation. 4. Construct the SVG separately and percent-encode it with `urllib.parse.quote()` before inserting it into the favicon URL. 5. Escape the final `href` value with `html_escape(..., quote=True)`. 6. Add tests for values containing semicolons, braces, quotes, ``, angle brackets, whitespace, oversized values, and malformed hexadecimal sequences. ]]>

other

Warning
Location
SKILL.md:1
Finding

Skill Manifest Describes a Different and Nonexistent Implementation

Content
View full analysis
- Generate a complete week of social media content for all platforms from a single topic or brand. Produces platform-optimized posts, a beautiful shareable HTML content calendar, hashtag suggestions, posting-time recommendations, and JSON export for scheduling tools. --- ``` It instructs users and agents to invoke a script that is absent from the package: ```bash python scripts/social_kit.py generate --topic 'sustainable fashion' --brand 'EcoThreads' python scripts/social_kit.py calendar content.json --output calendar.html echo 'organic coffee roastery in Brooklyn' | python scripts/social_kit.py --auto ``` The included executable instead identifies itself as a landing-page generator: ```python """ landing_builder.py — Generate beautiful, production-quality landing pages from a simple text description. Pure Python stdlib only. Output is a single standalone HTML file with embedded CSS (only external dep is Google Fonts). """ ``` Its actual command parser exposes landing-page build and auto-generation behavior: ```python def main(): parser = argparse.ArgumentParser( prog="landing_builder.py", description="Generate beautiful, modern landing pages from text descriptions.", ) subparsers = parser.add_subparsers(dest="command") build_parser = subparsers.add_parser("build", help="Build a landing page") build_parser.add_argument("--name", "-n", help="Business/product name") build_parser.add_argument("--desc", "-d", help="Short description") build_parser.add_argument("--theme", "- ...[truncated 2131 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The README presents a landing-page builder while the skill metadata claims it is a social-media content generator, creating a clear identity and capability mismatch. This kind of deceptive packaging can cause a host system or reviewer to authorize the skill for one purpose while it actually generates HTML/web content, which is especially risky because such output can introduce active content and external resource loading outside the declared scope.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The README extensively documents commands, outputs, themes, and HTML generation behavior that contradict the declared social-media purpose, reinforcing that the skill's real behavior differs from what integrators are told. In a skill ecosystem, this enables scope smuggling: users may invoke or install a seemingly low-risk content tool that actually produces deployable web pages and embedded third-party resources, bypassing policy expectations and trust boundaries.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill's declared purpose materially differs from the detected implementation behavior, which is a trust and transparency failure that can cause users or automated systems to invoke it under false assumptions. A skill presented as harmless social-media content generation but actually building unrelated HTML/pages and not performing the promised functions increases the risk of deceptive behavior, unsafe file generation, and bypass of review decisions based on the declared description.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file’s stated purpose and actual implementation are materially inconsistent with the skill manifest: it generates standalone landing-page HTML instead of social-media content/calendar artifacts. In an agent-skill ecosystem, this kind of capability mismatch is dangerous because users or orchestration systems may invoke the skill with one trust assumption while it performs unrelated file-generation behavior, increasing the chance of misuse, hidden functionality, or policy bypass.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · scripts/landing_builder.py (reported line 108)May include surrounding context.

python
collaborations.",
        "nav": ["Work", "About", "Contact"],
        "footer_tagline": "Design that matters.",
    },
    "restaurant": {
        "fonts": ("Poppins", "Inter"),
        "hero_img": "https://images.unsplash.com/photo-1517248135467-4c7edcad34c4?w=1200&q=80",
        "sections": ["hero", "features", "testimonials", "cta", "footer"],
        "feature_icons": ["🍽️", "🍷", "👨‍🍳", "🌿"],
        "features": [
            ("Seasonal Menu", "Farm-to-table dishes crafted with the freshest local ingredients."),
            ("Curated Wine List", "Over 200 selections hand-picked by our certified sommeliers."),
            ("Award-Winning Chef", "Michelin-recognized cuisine from our executive chef."),
            ("Cozy Atmosphere", "Warm, intimate setting perfect for any occasion."),
        ],
        "testimonials": [
            ("Food Critic Magazine", "★★★★★", "The best dining experience I've had this year. Every dish is a masterpiece."),

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The core logic is devoted to website section rendering, CSS generation, and HTML page assembly rather than social-media content generation. In a skill marketplace or agent runtime, such undisclosed behavior can mislead operators, expand the effective capability surface, and undermine code-review assumptions about what the skill is allowed to do.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README states that generated pages load Google Fonts and Unsplash placeholders but does not clearly warn users that opening the output will contact third-party services. While lower severity than the identity mismatch, this creates privacy and compliance risk because users may expect a standalone local HTML file yet inadvertently leak access metadata or violate offline/internal-use assumptions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The generated page hard-codes <html lang="en">, which imposes an English locale on all output regardless of the user's input or target audience. This is a natural-language policy issue because the file fixes a specific language/locale without offering opt-in or configuration.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.