postiz

Pass

Audited by Gen Agent Trust Hub on Jul 14, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool to execute mktg publish and mktg catalog commands. These operations are essential for managing social media integrations and distributing content. The use of these tools is strictly controlled through the allowed-tools configuration.
  • [EXTERNAL_DOWNLOADS]: The skill performs network requests to the Postiz API (e.g., api.postiz.com) to retrieve lists of connected integrations. This behavior is necessary for the skill to function as a social media scheduler and targets a well-known service.
  • [DATA_EXFILTRATION]: The skill transmits user-provided social media content and authentication tokens (POSTIZ_API_KEY) to the configured Postiz API instance. This data flow is the primary purpose of the skill and is documented for the user.
  • [PROMPT_INJECTION]: The skill ingests untrusted data from the brand/voice-profile.md file and user-provided social media copy. The risk of indirect prompt injection is mitigated because the skill acts solely as a distribution layer and does not interpret, rewrite, or execute the content. The ingestion process includes basic pipeline checks for control characters.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 14, 2026, 02:06 PM
Security Audit — agent-trust-hub — postiz