Postiz is a tool to schedule social media and chat posts to 28+ channels X, LinkedIn, LinkedIn Page, Reddit, Instagram, Facebook Page, Threads, YouTube, Google My Business, TikTok, Pinterest, Dribbble, Discord, Slack, Kick, Twitch, Mastodon, Bluesky, Lemmy, Farcaster, Telegram, Nostr, VK, Medium, Dev.to, Hashnode, WordPress, ListMonk owner avatar

Postiz is a tool to schedule social media and chat posts to 28+ channels X, LinkedIn, LinkedIn Page, Reddit, Instagram, Facebook Page, Threads, YouTube, Google My Business, TikTok, Pinterest, Dribbble, Discord, Slack, Kick, Twitch, Mastodon, Bluesky, Lemmy, Farcaster, Telegram, Nostr, VK, Medium, Dev.to, Hashnode, WordPress, ListMonk

Alert level: High

Postiz is a tool to schedule social media and chat posts to 28+ channels X, LinkedIn, LinkedIn Page, Reddit, Instagram, Facebook Page, Threads, YouTube, Google My Business, TikTok, Pinterest, Dribbble, Discord, Slack, Kick, Twitch, Mastodon, Bluesky, Lemmy, Farcaster, Telegram, Nostr, VK, Medium, Dev.to, Hashnode, WordPress, ListMonk

Locality:Hybrid
Data access:Sensitive
Actions:Write
Installs 3Downloads 998Stars 2Updated 204h ago

Why this rating

Deterministic checks triggered by the tool capabilities and evidence.

  • Locality: Hybrid

    Calls the Postiz public API at `api.postiz.com` and uses `platform.postiz.com` for API key management.

  • Data access: Sensitive

    Handles social account integrations, post content, and uploaded media (and can fetch media from a URL).

  • Action surface: Write

    Can schedule new posts and delete posts via the Postiz API.

Best practices

Follow these steps to reduce risk when using this skill.

  • Store `POSTIZ_API_KEY` in a secret manager or env var and rotate it if it is exposed.
  • Double-check channel integration IDs, dates/timezones, and post content before scheduling to avoid accidental public posts.
  • Be cautious with uploads-from-URL and only pull media from trusted sources; avoid ingesting private links unintentionally.

Evidence links

Public sources backing the indicator assignments.

Always be careful when navigating away from the website.

Max-risk rule

If any capability reaches a higher level, the entire indicator level bumps up to keep ratings deterministic and easy to scan.