Skills faceless Audit History
📦

Audit History

faceless - 1 audit

Aug 20, 2026, 01:24 AM

Most static findings are documentation false positives: API examples target Faceless.so, key references support authentication, and Markdown backticks are not Ruby execution. One unpinned npm execution risk is confirmed, and workflows lack explicit confirmation before credit charges or public posting.

4
Files scanned
1,409
Lines analyzed
6
Review items
0
False positives ignored

Confirmed security concerns (1)

Medium
Paid and Public Actions Lack Confirmation Guardrails
Workflows charge credits and publish or automate social content without requiring confirmation of cost, destination account, platform, schedule, or visibility.
The cited workflows explicitly charge credits, publish immediately, and enable recurring auto-posting, but they specify no final confirmation step.
Capability review items (1)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

High
Ruby/shell backtick execution
2. If not found, install it: `npm install -g faceless-cli` (or use `npx -y faceless-cli <command>` w
The skill installs or executes the latest unpinned faceless-cli package. A compromised release could execute arbitrary code without confirmation.

Risk Factors

📁 Filesystem access (2)
🔑 Env variables (33)
🌐 Network access (42)
⚙️ External commands (50)
Audited by: codex