social-reply-bot
Fail
Audited by Gen Agent Trust Hub on Aug 20, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill promotes a 'One-Line Install' pattern in
SKILL.md,README.md, andinstall.shthat downloads a shell script from a remote GitHub repository and pipes it directly into the bash interpreter (curl -fsSL ... | bash). This practice executes unverified remote code on the host system without local inspection. - [COMMAND_EXECUTION]: The
bot/browser.pyscript utilizessubprocess.run(shell=True)to execute commands via a CLI tool. It constructs these commands by concatenating strings with inputs derived from external web content (Reddit and X posts). The escaping mechanism used (replace("'", "\\'")) is insufficient for bash single-quoted strings, allowing an attacker to inject shell commands via specially crafted social media posts. - [PERSISTENCE_MECHANISMS]: The installation scripts (
install.shandsetup.sh) automatically register a macOS LaunchAgent (com.socialbot.daily.plist) in the user's~/Library/LaunchAgentsdirectory and load it usinglaunchctl. This ensures the skill's automation runs daily at 10:05 AM, establishing a persistent presence on the user's system. - [INDIRECT_PROMPT_INJECTION]: In
bot/ai_engine.py, the skill ingests untrusted post content from Reddit and X and interpolates it directly into an AI prompt for Claude. The instructions lack boundary markers (e.g., XML tags or delimiters) or robust sanitization, creating a significant surface for indirect prompt injection where an attacker could influence the agent's behavior through post content.
Recommendations
- HIGH: Downloads and executes remote code from: https://raw.githubusercontent.com/mguozhen/social-bot/main/install.sh - DO NOT USE without thorough review
- AI detected serious security threats
Audit Metadata