postiz
Warn
Audited by Socket on Apr 27, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
Overall this skill is functional and mostly aligned with its stated purpose, but it is higher risk than a normal documentation skill because it can take live public posting actions on behalf of the user, stores/uses credentials, and allows API traffic to be redirected via POSTIZ_API_URL. The unrelated agent-media recommendation further broadens the trust boundary. Best classified as SUSPICIOUS rather than malicious.
Confidence: 83%Severity: 68%
Audit Metadata