meta-fb-inbox
What this skill does
The skill is designed to automate interactions with the Meta Business Suite (Facebook Page Inbox), allowing users to check messages, reply to customers, and manage inbox operations via browser automat
github/leoyeai - Configuration Risk - 2.1k stars
Threat analysis
Skill info
pkg:github/LeoYeAI/openclaw-master-skills@e5199b5?skill=meta-fb-inboxAssessments (3)
Configuration Risk
Configuration Risk via local-llm-review
scripts/setup.js
The setup wizard allows users to input Facebook page URLs, which are then stored in a `config.json` file. If this file is not properly secured, it could expose sensitive URLs or credentials.Path Traversal Risk
Path Traversal Risk via local-llm-review
SKILL.md
The documentation explicitly warns against using `../` or absolute paths, which suggests that the skill may be vulnerable to path traversal attacks if not properly restricted.Configuration Management Risk
Configuration Management Risk via local-llm-review
SKILL.md
The skill relies on a `config.json` file that is not described as being encrypted or protected. If this file is exposed, it could reveal sensitive information such as Facebook page URLs.Badge
Add the Anomity scan badge for meta-fb-inbox to your README.
How Anomity governs this at runtime
Scan-time vetting tells you what a skill says it will do. Anomity's Endpoint Sensor sees what agents actually do: it discovers skills alongside every other AI artifact on the endpoint, and runtime governance can allow, deny, or log the tool calls a skill triggers. Policy violations route to your SIEM, Slack, email, or Jira, backed by a queryable 90-day audit trail.
Book a 30-minute demo to see your own skill inventory.
Methodology and disputes
Every skill is assessed by the Anomity Skill Intelligence engine against its public source; findings indicate risk patterns, not confirmed exploitation. Maintainer of meta-fb-inbox? Report an issue or request a rescan.




