Your LinkedIn & Twitter Assistant by Reepl

Security checks across malware telemetry and agentic risk

Overview

This Reepl skill fits its stated social-media management purpose, but it gives agents real posting, deletion, and persistent profile-changing powers without consistent confirmation guidance for every high-impact action.

Install only if you trust Reepl with your connected LinkedIn/Twitter workflow and are comfortable giving an agent authority over drafts, scheduled posts, comments, contacts, and voice-profile state. Before using it, require the agent to show exact content, target account, IDs/titles, visibility, and timing before any publish, schedule, comment, delete, contact-list, or voice-profile update.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill documents destructive delete operations without consistently requiring explicit user confirmation immediately before execution. In an agent setting, that omission can lead to accidental or prompt-induced deletion of drafts or scheduled posts, causing irreversible loss of user content or workflow disruption.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
`update_voice_profile` modifies persisted user profile data that affects future content generation, but the documentation does not clearly warn that this is a profile-changing operation requiring explicit user awareness and consent. An agent could update long-lived preferences or learned patterns based on inferred behavior, causing lasting misalignment or unauthorized changes to the user's writing profile.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
Permanent carousel draft deletion is documented without an explicit confirmation gate, despite the operation being irreversible. In a content-management skill with many similarly named drafts, an agent could easily delete the wrong asset due to ambiguity, prompt injection, or user misunderstanding.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal