socialclaw

Warn

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of external code via the npm registry (socialclaw@0.1.12) and a community GitHub repository (ndesv21/socialclaw). These dependencies originate from a third-party community contributor and are not from a verified or well-known organization.\n- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface by processing untrusted data alongside high-privilege publishing capabilities.\n
  • Ingestion points: Processes user-provided post content during campaign creation (Step 1) and external performance metrics from the SocialClaw API (Step 5).\n
  • Boundary markers: No explicit delimiters or instructions are specified to separate data from instructions or to prevent the agent from obeying instructions embedded in user content or API responses.\n
  • Capability inventory: The skill can perform state-changing operations including publishing, scheduling, and deleting content on 13 major social media platforms.\n
  • Sanitization: The instructions do not define any validation, escaping, or filtering protocols for the external data before it is processed by the agent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 22, 2026, 09:45 AM
Security Audit — agent-trust-hub — socialclaw