Back to skill

Security audit

social-media-kit

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent local social-media content generator, with a real but bounded HTML escaping risk when rendering untrusted calendar JSON.

Install only if you are comfortable with a local CLI that reads user-supplied calendar JSON and writes generated JSON/HTML files. Avoid opening or sharing calendars generated from untrusted JSON until the HTML escaping and content-type validation issues are fixed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/social_kit.py:891
Finding

Stored HTML Injection in Generated Content Calendars

Content
View full analysis
{meta['brand']} — Social Media Content Calendar ``` ```python
🎯 {theme['name']}
``` ```python return f"""
{_esc(post['day_name'])} · Day {post['day']}
{_esc(post['date'])} · ⏰ {_esc(post['best_time'])}
{post['content_type_emoji']} {post['content_type_label']} ``` The `calendar` command loads user-supplied JSON directly: ```python with open(json_path, "r", encoding="utf-8") as f: calendar_data = json.load(f) generate_html_calendar(calendar_data, output_path) ``` ### Technical Analysis Several values are interpolated directly into the generated HTML without contextual escaping: - `meta['brand']` is inserted into the `` element. - `theme['name']` is inserted into an HTML element. - `post['content_type']` is inserted into CSS class attributes. - `content_type_emoji` and `content_type_label` are inserted as HTML content. These values can originate from command-line or stdin input, and the `calendar` command also accepts an arbitrary JSON document without schema validation. Although the project defines an `_esc()` function and uses it for several other fields, the affected values bypass that function. For example, a crafted brand value containing: ```html ``` would terminate the existing ti ...[truncated 1855 chars]
Remediation
View remediation
{_esc(meta['brand'])} — Social Media Content Calendar
🎯 {_esc(theme['name'])}
``` 2. Escape display fields in post cards: ```python {_esc(post['content_type_emoji'])} {_esc(post['content_type_label'])} ``` 3. Do not rely on HTML escaping for CSS class fragments. Validate `content_type` against a strict allowlist: ```python allowed_types = set(CONTENT_TYPES) ct = post.get("content_type") if ct not in allowed_types: raise ValueError(f"Invalid content type: {ct!r}") ``` 4. Validate imported JSON before rendering. Enforce expected types, required fields, supported platform names, content-type values, bounded numeric fields, and reasonable string lengths. 5. Prefer a template engine with automatic HTML escaping and use explicit validation for values inserted into attributes or CSS class names. 6. Add regression tests using payloads that attempt to escape title, element-content, and attribute contexts. Verify that generated output contains escaped text and no executable `
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

md
python scripts/social_kit.py generate --topic 'sustainable fashion' --brand 'EcoThreads'

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

md
python scripts/social_kit.py generate --topic 'sustainable fashion' --brand 'EcoThreads'

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

md
python scripts/social_kit.py generate --topic 'sustainable fashion' --brand 'EcoThreads'

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

md
python scripts/social_kit.py generate --topic 'sustainable fashion' --brand 'EcoThreads'

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 87)May include surrounding context.

md
python scripts/social_kit.py generate --topic 'sustainable fashion' --brand 'EcoThreads'

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 106)May include surrounding context.

md
python scripts/social_kit.py generate --topic 'sustainable fashion' --brand 'EcoThreads'

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 112)May include surrounding context.

md
python scripts/social_kit.py generate --topic 'sustainable fashion' --brand 'EcoThreads'

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill documentation advertises file-reading and file-writing behavior via generated JSON and HTML outputs, but it does not declare any explicit tool scope such as permissions or allowed-tools. That mismatch weakens least-privilege guarantees and can allow broader-than-expected filesystem access if the runtime infers or grants capabilities implicitly.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.