baoyu-post-to-x

Warn

Audited by Snyk on Aug 21, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). In scripts/x-article.ts, the agent reads user-supplied Markdown from a provided markdownPath, converts it via scripts/md-to-html.ts into HTML, and then injects that HTML into the X Articles editor at runtime (direct free-text ingestion from outsider-authored content via the skill input path).

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (medium risk: 0.40). The skill instructs the agent to kill Chrome CDP processes automatically (pkill) and to run a remote installer (curl | bash) which modify system processes and install software, though it does not request sudo, create users, or edit privileged system files, so it is a moderate risk.

Issues (2)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W013
MEDIUM

Attempt to modify system services in skill instructions.

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 21, 2026, 02:09 AM
Issues
2