socialclaw
Warn
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of external code via the npm registry (
socialclaw@0.1.12) and a community GitHub repository (ndesv21/socialclaw). These dependencies originate from a third-party community contributor and are not from a verified or well-known organization.\n- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface by processing untrusted data alongside high-privilege publishing capabilities.\n - Ingestion points: Processes user-provided post content during campaign creation (Step 1) and external performance metrics from the SocialClaw API (Step 5).\n
- Boundary markers: No explicit delimiters or instructions are specified to separate data from instructions or to prevent the agent from obeying instructions embedded in user content or API responses.\n
- Capability inventory: The skill can perform state-changing operations including publishing, scheduling, and deleting content on 13 major social media platforms.\n
- Sanitization: The instructions do not define any validation, escaping, or filtering protocols for the external data before it is processed by the agent.
Audit Metadata