posteverywhere

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFE
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill manages API keys using security best practices. It stores credentials in a local configuration file (~/.posteverywhere/config.json) with restricted file permissions (0600). The CLI implementation also uses a muted readline stream (askSecret) to ensure that sensitive tokens, such as bot tokens or app passwords, are never echoed to the screen during user input.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided content and external media URLs, which are potential ingestion points for indirect prompt injection. To mitigate this risk, the instructions explicitly require the agent to confirm both the content and the target accounts with the user before any publishing action occurs, ensuring human oversight.\n- [EXTERNAL_DOWNLOADS]: The skill interacts exclusively with the vendor's official domain (posteverywhere.ai) for API operations and media uploads. These network operations are intrinsic to the tool's primary purpose and do not involve untrusted or unverified third-party services.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 10:12 AM
Security Audit — agent-trust-hub — posteverywhere