SkillTotal

Is Claude Skill Social Post safe?

No malicious indicators - review capabilities before installing
Notable — review in context (capabilities are not malware):
  • Python shell/command execution
  • Node.js shell/command execution
  • Node.js dynamic code execution

repo is an AI directory analyzed by SkillTotal's deterministic static scanner. The scan found no malicious indicators, though 8 risky constructs are reported for review. It can: dynamic code execution, filesystem read, filesystem write, mcp tools detected, network egress and shell execution — capabilities are what the code can do, not a verdict on intent. Risk score 0/100 (low).

repo

directory · https://github.com/Hao0321/claude-skill-social-post
LOW
0
/ 100 risk score
Snapshot · scanned Sep 24, 2026 · repo@c2641ba · engine 0.53.0 / ruleset 60

Automated static-analysis result. It can contain false positives and false negatives, and is not a claim about the intent of Claude Skill Social Post's authors. Report a false positive.

Capabilities — what this component can do (not a risk score):
dynamic code executionfilesystem readfilesystem writemcp tools detectednetwork egressshell execution

Behavioral traits

How this component maps to the CSA agentic threat model. Descriptive — it never affects the risk score.

Tool surface
Tool Usage
Execution authority
Tool Access Control / Direct Tool Access
Filesystem reach
Tool Execution Context
Network egress
Interaction & Communication / Direct Communication

Findings (8)

HIGHNode.js dynamic code executionST-DYN-NODE

The code turns strings into live code at runtime (eval / new Function / exec).

'eval("import(\\"./evil3.mjs\\")"); Function("return import(\\"./evil4.mjs\\")")();',
'globalThis.eval("import(\\"./evil5.mjs\\")"); globalThis.Function("return 1")();',

Why it matters: If those strings aren't fixed and trusted, they become a way to run arbitrary code.

Fix: Avoid evaluating dynamically constructed code; if unavoidable, ensure the input is a trusted constant and never derived from external data.

HIGHNode.js shell/command executionST-SHELL-NODE

The component can run operating-system commands or spawn processes.

Why it matters: Powerful and often legitimate — confirm the commands aren't built from untrusted input.

Fix: Confirm the command and its arguments are fully controlled and not derived from untrusted input; prefer execFile with an argument array.

HIGHPython shell/command executionST-SHELL-PY

The component can run operating-system commands or spawn processes.

completed = subprocess.run(
            [node, "--input-type=module", "-e", NODE_PARSE_PROGRAM, str(parser)],
            cwd=root,
            check=False,
            capture_output=True,
            input=payload,
            timeout=30, …
processes.append(subprocess.Popen(
            [sys.executable, "-c", wrapper, str(gate), str(ready), *cli],
            stdout=subprocess.PIPE, stderr=subprocess.PIPE, text=True,
            encoding="utf-8", env=clean_env,
        ))
delayed = subprocess.Popen(
        [sys.executable, "-c", wrapper, str(script), str(ready), str(release), *cli],
        stdout=subprocess.PIPE, stderr=subprocess.PIPE, text=True, encoding="utf-8",
    )
children = [subprocess.Popen(argv, stdout=subprocess.PIPE, stderr=subprocess.PIPE,
                                         text=True, encoding="utf-8", shell=False) for _ in range(2)]
completed = subprocess.run(
        [sys.executable, str(script), *args, "--root", str(root)],
        capture_output=True, text=True, encoding="utf-8", check=False, env=clean_env,
    )
completed = subprocess.run(
        [node, str(runner)],
        cwd=root,
        check=False,
        capture_output=True,
        text=True,
        timeout=30,
    )

Why it matters: Powerful and often legitimate — confirm the commands aren't built from untrusted input.

Fix: Confirm the command and its arguments are fully controlled and not derived from untrusted input; avoid shell=True.

MEDIUMPython filesystem readST-FS-PY-READ

The component reads files from disk.

metadata_value = json.loads(METADATA.read_text(encoding="utf-8-sig"))
text = source.read_text(encoding="utf-8-sig")
summary = json.loads(path.read_text(encoding="utf-8"))
package = json.loads(PACKAGE.read_text(encoding="utf-8"))
projection = json.loads(PROJECTION.read_text(encoding="utf-8"))
projection = json.loads(PROJECTION.read_text(encoding="utf-8"))
projection = json.loads(PROJECTION.read_text(encoding="utf-8"))
package = json.loads(PACKAGE.read_text(encoding="utf-8"))
value = json.loads(path.read_text(encoding="utf-8-sig"))
json.loads(Path(value).read_text(encoding="utf-8-sig"))
digest.update(path.read_bytes())
destination: destination.read_bytes() if destination.exists() else None
parser.feed(fixture_path.read_text(encoding="utf-8"))
for row in reply_path.read_text(encoding="utf-8").splitlines()
(root / relative).read_text(encoding="utf-8")
json.loads(row) for row in (
                root / "data" / "browser_scan_requests.jsonl"
            ).read_text(encoding="utf-8").splitlines()
for row in request_path.read_text(encoding="utf-8").splitlines()
before = request_path.read_text(encoding="utf-8")
if "DRY_RUN valid" not in dry.stdout or request_path.read_text(encoding="utf-8") != before:
for row in request_path.read_text(encoding="utf-8").splitlines()

Why it matters: Usually legitimate, but worth confirming it can't be steered into reading sensitive files.

Fix: Confirm which files are read and that paths cannot be influenced by untrusted input to reach sensitive locations.

MEDIUMPython filesystem write/deleteST-FS-PY-WRITE

The component writes or deletes files on disk.

OUTPUT.write_text(rendered, encoding="utf-8")
temporary.write_text(json.dumps(value, ensure_ascii=False, indent=2) + "\n", encoding="utf-8")
oversized.write_bytes(b"x" * (MAX_RECEIPT_BYTES + 1))
shutil.copyfile(source, temporary)
destination.write_bytes(original)
source.write_text(json.dumps(scanned, ensure_ascii=False), encoding="utf-8")
path.write_text(json.dumps(value, ensure_ascii=False), encoding="utf-8")
path.write_text(json.dumps(policy), encoding="utf-8")
path.write_text(
        "".join(json.dumps(row, ensure_ascii=False) + "\n" for row in rows),
        encoding="utf-8",
    )
policy_path.write_text(json.dumps(policy), encoding="utf-8")
policy_path.write_text(json.dumps(policy), encoding="utf-8")
path.write_text(json.dumps(payload, ensure_ascii=False), encoding="utf-8")
reply_path.write_text(
        "\n".join(json.dumps(row, ensure_ascii=False) for row in rows) + "\n",
        encoding="utf-8",
    )
(root / "references" / "comment-policy.json").write_text(json.dumps(policy), encoding="utf-8")
(root / "data" / "comment_events.jsonl").write_text("", encoding="utf-8")
(root / "data" / "reply_events.jsonl").write_text("", encoding="utf-8")
(root / "references" / "comment-policy.json").write_text(
        json.dumps(fixture_policy), encoding="utf-8",
    )
source.write_text(
        json.dumps(sample_comment("cli", observed_at="2026-01-01T00:00:00+08:00")),
        encoding="utf-8",
    )
source.write_text(json.dumps(emoji_comment, ensure_ascii=False), encoding="utf-8")
path.write_text(content, encoding="utf-8")

Why it matters: Usually legitimate, but worth confirming the paths can't be controlled by untrusted input.

Fix: Confirm which files are written/deleted and that paths cannot be influenced by untrusted input.

MEDIUMNode.js network egressST-NET-NODE

The component makes outbound network requests.

Why it matters: Usually legitimate, but confirm the destinations are expected and no sensitive data leaves.

Fix: Confirm the destination hosts are expected and that no sensitive data is sent off-host.

MEDIUMPython network egressST-NET-PY

The component makes outbound network requests.

request = requests.get(request_id) if isinstance(request_id, str) else None

Why it matters: Usually legitimate, but confirm the destinations are expected and no sensitive data leaves.

Fix: Confirm the destination hosts are expected and that no sensitive data is sent off-host.

LOWMCP tool surface detectedST-MCP-DETECTED

An MCP tool surface (manifest or tool definitions) was found.

Why it matters: Just context — review which tools it offers and their permissions.

Fix: Review the declared MCP tools and their permissions.

Check your own component

Run the same evidence-backed scan on any MCP server, agent skill, or package.

Scan your own component

How we determine this: deterministic static analysis (regex + AST), evidence-anchored, no code execution. Methodology →