Automate generation and multi-platform posting of 50+ viral videos from a single product image with A/B hook testing and analytics.
Security Analysis
high confidenceThe skill's description promises fully automated multi-platform posting and analytics, but the package lacks the code, credentials, and install/runtime requirements needed to actually do that — the pieces don't line up.
The skill claims autoposting, platform integrations, analytics, and A/B testing across TikTok/Instagram/Facebook/Twitter/YouTube, but declares no required credentials, no config paths, and no install steps. Real multi-platform posting requires API keys/tokens and integration code; those are missing from the manifest.
SKILL.md instructs running scripts (e.g., scripts/generate_videos.py, scripts/autopilot.py), scheduling posts, tracking views/watch-time/conversions, and interacting with PostBridge. However the package contains only SKILL.md and package.json — the referenced scripts and any code to call platform APIs or collect analytics are absent, which is an incoherence and a potential red flag.
There is no install spec (instruction-only), so nothing will be downloaded or installed automatically. That minimally reduces supply-chain risk, but also means the skill as-published is incomplete (it points at scripts that aren't present).
The skill's functionality would reasonably require multiple service credentials (social platform API keys/tokens, PostBridge credentials, possibly analytics or affiliate tracking credentials), but requires.env lists none. This mismatch suggests either missing declarations or that the skill's instructions expect users to supply credentials ad-hoc, which increases risk.
The skill is not always-enabled and allows normal model invocation. It does not request elevated or persistent platform-level privileges in the manifest. The real concern is that its intended autonomous behavior (autopilot posting) would need credentials; those are not declared.
Guidance
Do not install or run this skill yet. Before proceeding, ask the publisher for the full source repository and verify that the referenced scripts actually exist. Confirm exactly which API credentials are required (platform tokens, PostBridge credentials, analytics access), how they are stored/secured, and whether the skill will post on your behalf or require manual authorization flows. Check platform terms of service for automated posting and affiliate/UTM usage. If you must test, do so in an isolated environment with throwaway accounts and never supply production API keys until you've audited the code. If the publisher cannot provide code or clear credential requirements, treat the skill as incomplete/untrusted.
Latest Release
v2.0.0
v2.0.0 - Based on POST AI concept but with 5x more content (50+ vs 10 videos), full autopilot mode, A/B testing hooks, viral score prediction, PostBridge integration. Complete automation system for affiliate content generation.
More by @oyi77
Published by @oyi77 on ClawHub