postiz-agent
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external, untrusted content from social media platforms (comments, DMs, replies), which is a primary vector for indirect prompt injection. However, it implements mandatory, fail-closed screening protocols.
- Ingestion points: External content is fetched via
postiz posts:*,analytics:*, andintegrations:triggercommands. - Boundary markers: The skill instructions explicitly mandate screening all external text before reading or acting on it.
- Capability inventory: The skill can execute CLI commands (
postiz), perform network requests to a local API, and upload files. - Sanitization: The
scripts/screen.shscript implements a two-stage defense: a programmatic gate using regex to catch binary blobs, zero-width characters, and common injection sigils, followed by a local LLM classifier to detect adversarial intent. - [COMMAND_EXECUTION]: The skill executes the
postizCLI anddocker compose. These are scoped to the self-hosted environment and are restricted by an opt-in gate (scripts/gate.sh) that requires a specific project declaration inAGENTS.mdorCHOICES.mdto function. - [DATA_EXFILTRATION]: While the skill makes network requests, they target a local or user-defined
api-url(defaulting tolocalhost). The instructions warn against piping unscreened output to feedback sinks, mitigating the risk of data exfiltration via indirect injection. - [OBFUSCATION]: The
scripts/screen.shscript specifically looks for and blocks obfuscation techniques such as zero-width characters, bidi overrides, and long encoded blobs (Base64/Hex) in external data.
Audit Metadata