postiz-agent

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external, untrusted content from social media platforms (comments, DMs, replies), which is a primary vector for indirect prompt injection. However, it implements mandatory, fail-closed screening protocols.
  • Ingestion points: External content is fetched via postiz posts:*, analytics:*, and integrations:trigger commands.
  • Boundary markers: The skill instructions explicitly mandate screening all external text before reading or acting on it.
  • Capability inventory: The skill can execute CLI commands (postiz), perform network requests to a local API, and upload files.
  • Sanitization: The scripts/screen.sh script implements a two-stage defense: a programmatic gate using regex to catch binary blobs, zero-width characters, and common injection sigils, followed by a local LLM classifier to detect adversarial intent.
  • [COMMAND_EXECUTION]: The skill executes the postiz CLI and docker compose. These are scoped to the self-hosted environment and are restricted by an opt-in gate (scripts/gate.sh) that requires a specific project declaration in AGENTS.md or CHOICES.md to function.
  • [DATA_EXFILTRATION]: While the skill makes network requests, they target a local or user-defined api-url (defaulting to localhost). The instructions warn against piping unscreened output to feedback sinks, mitigating the risk of data exfiltration via indirect injection.
  • [OBFUSCATION]: The scripts/screen.sh script specifically looks for and blocks obfuscation techniques such as zero-width characters, bidi overrides, and long encoded blobs (Base64/Hex) in external data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 08:52 PM
Security Audit — agent-trust-hub — postiz-agent