Is Claude Skill Social Post safe?
- Python shell/command execution
- Node.js shell/command execution
- Node.js dynamic code execution
repo is an AI directory analyzed by SkillTotal's deterministic static scanner. The scan found no malicious indicators, though 8 risky constructs are reported for review. It can: dynamic code execution, filesystem read, filesystem write, mcp tools detected, network egress and shell execution — capabilities are what the code can do, not a verdict on intent. Risk score 0/100 (low).
repo
Automated static-analysis result. It can contain false positives and false negatives, and is not a claim about the intent of Claude Skill Social Post's authors. Report a false positive.
Behavioral traits
How this component maps to the CSA agentic threat model. Descriptive — it never affects the risk score.
Findings (8)
The code turns strings into live code at runtime (eval / new Function / exec).
'eval("import(\\"./evil3.mjs\\")"); Function("return import(\\"./evil4.mjs\\")")();','globalThis.eval("import(\\"./evil5.mjs\\")"); globalThis.Function("return 1")();',Why it matters: If those strings aren't fixed and trusted, they become a way to run arbitrary code.
Fix: Avoid evaluating dynamically constructed code; if unavoidable, ensure the input is a trusted constant and never derived from external data.
The component can run operating-system commands or spawn processes.
import { spawn } from "node:child_process";const child = spawn("python", [const child = spawn("python", args, {const child = spawn("python", [Why it matters: Powerful and often legitimate — confirm the commands aren't built from untrusted input.
Fix: Confirm the command and its arguments are fully controlled and not derived from untrusted input; prefer execFile with an argument array.
The component can run operating-system commands or spawn processes.
completed = subprocess.run(
[node, "--input-type=module", "-e", NODE_PARSE_PROGRAM, str(parser)],
cwd=root,
check=False,
capture_output=True,
input=payload,
timeout=30, …processes.append(subprocess.Popen(
[sys.executable, "-c", wrapper, str(gate), str(ready), *cli],
stdout=subprocess.PIPE, stderr=subprocess.PIPE, text=True,
encoding="utf-8", env=clean_env,
))delayed = subprocess.Popen(
[sys.executable, "-c", wrapper, str(script), str(ready), str(release), *cli],
stdout=subprocess.PIPE, stderr=subprocess.PIPE, text=True, encoding="utf-8",
)children = [subprocess.Popen(argv, stdout=subprocess.PIPE, stderr=subprocess.PIPE,
text=True, encoding="utf-8", shell=False) for _ in range(2)]completed = subprocess.run(
[sys.executable, str(script), *args, "--root", str(root)],
capture_output=True, text=True, encoding="utf-8", check=False, env=clean_env,
)completed = subprocess.run(
[node, str(runner)],
cwd=root,
check=False,
capture_output=True,
text=True,
timeout=30,
)Why it matters: Powerful and often legitimate — confirm the commands aren't built from untrusted input.
Fix: Confirm the command and its arguments are fully controlled and not derived from untrusted input; avoid shell=True.
The component reads files from disk.
metadata_value = json.loads(METADATA.read_text(encoding="utf-8-sig"))
text = source.read_text(encoding="utf-8-sig")
data = source.read_bytes()
summary = json.loads(path.read_text(encoding="utf-8"))
raw = CANONICAL.read_bytes()
package = json.loads(PACKAGE.read_text(encoding="utf-8"))
projection = json.loads(PROJECTION.read_text(encoding="utf-8"))
projection = json.loads(PROJECTION.read_text(encoding="utf-8"))
projection = json.loads(PROJECTION.read_text(encoding="utf-8"))
raw = CANONICAL.read_bytes()
package = json.loads(PACKAGE.read_text(encoding="utf-8"))
value = json.loads(path.read_text(encoding="utf-8-sig"))
json.loads(Path(value).read_text(encoding="utf-8-sig"))
digest.update(path.read_bytes())
destination: destination.read_bytes() if destination.exists() else None
parser.feed(fixture_path.read_text(encoding="utf-8"))
for row in reply_path.read_text(encoding="utf-8").splitlines()
(root / relative).read_text(encoding="utf-8")
if comment_path.read_text(encoding="utf-8"):
json.loads(row) for row in (
root / "data" / "browser_scan_requests.jsonl"
).read_text(encoding="utf-8").splitlines()if comment_path.read_text(encoding="utf-8"):
for row in request_path.read_text(encoding="utf-8").splitlines()
before = request_path.read_text(encoding="utf-8")
if "DRY_RUN valid" not in dry.stdout or request_path.read_text(encoding="utf-8") != before:
for row in request_path.read_text(encoding="utf-8").splitlines()
Why it matters: Usually legitimate, but worth confirming it can't be steered into reading sensitive files.
Fix: Confirm which files are read and that paths cannot be influenced by untrusted input to reach sensitive locations.
The component writes or deletes files on disk.
OUTPUT.write_text(rendered, encoding="utf-8")
temporary.write_text(json.dumps(value, ensure_ascii=False, indent=2) + "\n", encoding="utf-8")
valid.write_bytes(canonical_json_bytes(value))
malformed.write_bytes(b"{not-json}\n")oversized.write_bytes(b"x" * (MAX_RECEIPT_BYTES + 1))
target.write_bytes(canonical_json_bytes(value))
shutil.copyfile(source, temporary)
destination.write_bytes(original)
source.write_text(json.dumps(scanned, ensure_ascii=False), encoding="utf-8")
path.write_text(json.dumps(value, ensure_ascii=False), encoding="utf-8")
path.write_text(json.dumps(policy), encoding="utf-8")
gate.write_text("go", encoding="utf-8")release.write_text("committed", encoding="utf-8")path.write_text(
"".join(json.dumps(row, ensure_ascii=False) + "\n" for row in rows),
encoding="utf-8",
)policy_path.write_text(json.dumps(policy), encoding="utf-8")
policy_path.write_text(json.dumps(policy), encoding="utf-8")
path.write_text(json.dumps(payload, ensure_ascii=False), encoding="utf-8")
reply_path.write_text(
"\n".join(json.dumps(row, ensure_ascii=False) for row in rows) + "\n",
encoding="utf-8",
)(root / "references" / "comment-policy.json").write_text(json.dumps(policy), encoding="utf-8")
(root / "data" / "comment_events.jsonl").write_text("", encoding="utf-8")(root / "data" / "reply_events.jsonl").write_text("", encoding="utf-8")(root / "references" / "comment-policy.json").write_text(
json.dumps(fixture_policy), encoding="utf-8",
)source.write_text(
json.dumps(sample_comment("cli", observed_at="2026-01-01T00:00:00+08:00")),
encoding="utf-8",
)source.write_text(json.dumps(emoji_comment, ensure_ascii=False), encoding="utf-8")
path.write_text(content, encoding="utf-8")
Why it matters: Usually legitimate, but worth confirming the paths can't be controlled by untrusted input.
Fix: Confirm which files are written/deleted and that paths cannot be influenced by untrusted input.
The component makes outbound network requests.
import { createServer } from "node:http";Why it matters: Usually legitimate, but confirm the destinations are expected and no sensitive data leaves.
Fix: Confirm the destination hosts are expected and that no sensitive data is sent off-host.
The component makes outbound network requests.
request = requests.get(request_id) if isinstance(request_id, str) else None
Why it matters: Usually legitimate, but confirm the destinations are expected and no sensitive data leaves.
Fix: Confirm the destination hosts are expected and that no sensitive data is sent off-host.
An MCP tool surface (manifest or tool definitions) was found.
Why it matters: Just context — review which tools it offers and their permissions.
Fix: Review the declared MCP tools and their permissions.
Check your own component
Run the same evidence-backed scan on any MCP server, agent skill, or package.
Scan your own componentHow we determine this: deterministic static analysis (regex + AST), evidence-anchored, no code execution. Methodology →