social-reply-bot

Fail

Audited by Gen Agent Trust Hub on Aug 20, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill promotes a 'One-Line Install' pattern in SKILL.md, README.md, and install.sh that downloads a shell script from a remote GitHub repository and pipes it directly into the bash interpreter (curl -fsSL ... | bash). This practice executes unverified remote code on the host system without local inspection.
  • [COMMAND_EXECUTION]: The bot/browser.py script utilizes subprocess.run(shell=True) to execute commands via a CLI tool. It constructs these commands by concatenating strings with inputs derived from external web content (Reddit and X posts). The escaping mechanism used (replace("'", "\\'")) is insufficient for bash single-quoted strings, allowing an attacker to inject shell commands via specially crafted social media posts.
  • [PERSISTENCE_MECHANISMS]: The installation scripts (install.sh and setup.sh) automatically register a macOS LaunchAgent (com.socialbot.daily.plist) in the user's ~/Library/LaunchAgents directory and load it using launchctl. This ensures the skill's automation runs daily at 10:05 AM, establishing a persistent presence on the user's system.
  • [INDIRECT_PROMPT_INJECTION]: In bot/ai_engine.py, the skill ingests untrusted post content from Reddit and X and interpolates it directly into an AI prompt for Claude. The instructions lack boundary markers (e.g., XML tags or delimiters) or robust sanitization, creating a significant surface for indirect prompt injection where an attacker could influence the agent's behavior through post content.
Recommendations
  • HIGH: Downloads and executes remote code from: https://raw.githubusercontent.com/mguozhen/social-bot/main/install.sh - DO NOT USE without thorough review
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 20, 2026, 02:29 PM
Security Audit — agent-trust-hub — social-reply-bot