social-publisher
Warn
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to install two third-party packages from the NPM registry.
- Evidence:
npm install -g socialclaw@0.1.12andopenclaw plugins install npm:@xquik/tweetclaw@1.6.31. - The
socialclawpackage is the primary tool for the skill's functionality, while@xquik/tweetclawis an optional plugin for retrieving X (Twitter) evidence packets. Both packages originate from non-trusted external sources. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from social media providers and local files which could contain malicious instructions.
- Ingestion points: The skill reads social media account lists (
socialclaw accounts list), post delivery status and analytics (socialclaw status), and campaign research input from the TweetClaw plugin (SKILL.md). - Boundary markers: No explicit boundary markers or instructions to ignore embedded commands are present in the processing logic described.
- Capability inventory: The skill possesses the ability to perform network operations (publishing posts to 13 platforms), write to the local file system (
schedule.json), and execute shell commands via thesocialclawandtweetclawCLIs. - Sanitization: The instructions do not mention sanitization, validation, or escaping of the data retrieved from external social media signals before it is used to influence future scheduling or publishing actions.
- [COMMAND_EXECUTION]: The skill relies heavily on the execution of CLI tools (
socialclaw,openclaw) with various arguments, including file paths and JSON configurations, providing a wide command execution surface. - Evidence: Multiple command patterns such as
socialclaw apply -f schedule.json,socialclaw assets upload --file ./image.png, andopenclaw plugins install.
Audit Metadata