Security audit
Comments Monitor Reply
Security checks for vulnerabilities and agentic risk
Overview
This skill is disclosed as a social-media comment automation tool, but it can use account cookies or tokens to automatically post public replies across multiple platforms.
Review before installing. Use least-privilege platform API tokens instead of main-account cookies where possible, test with a low-risk account, enable human approval for replies, limit enabled platforms, verify the external repository before running npm install, and confirm how credentials, logs, exports, and webhook payloads are stored and deleted.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
