postiz

Fail

Audited by Socket on Feb 28, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This document is a usage guide for the Postiz CLI and does not contain obvious embedded malware or intentionally obfuscated malicious code. The principal risks are operational and supply-chain: (1) credential forwarding if users set POSTIZ_API_URL to an attacker-controlled endpoint, (2) privacy/exfiltration of media/content to remote Postiz endpoints (expected behavior), and (3) expanded trust surface when chaining third-party media generators like agent-media. Recommendations: treat POSTIZ_API_KEY as sensitive, verify and prefer the official POSTIZ_API_URL over custom endpoints, ensure TLS/certificate verification for any custom endpoints, avoid passing the API key to untrusted hosts or scripts, and vet third-party media generators before integrating them into automation pipelines.

Confidence: 98%Severity: 90%
Audit Metadata
Analyzed At
Feb 28, 2026, 01:31 PM
Package URL
pkg:socket/skills-sh/gitroomhq%2Fpostiz-agent%2Fpostiz%2F@c5d1bf5f7e95a71e230fc19ae2150ddd9c549854