Back to skill

Security audit

Instagram Collector

Security checks across malware telemetry and agentic risk

Overview

This instruction-only skill coherently collects public Instagram profile metrics through Apify and does not show hidden, destructive, or unrelated behavior.

Install this only if you intend to use Apify for Instagram profile scraping. Use a dedicated Apify token, monitor quota or charges, and make sure users are comfortable with requested Instagram handles and scraper results being processed by Apify.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly sends user-supplied Instagram handles and associated profile retrieval requests to Apify, a third-party service, but does not disclose that external transmission to users. This creates a privacy and transparency issue because users and downstream operators may not realize their inputs and related metadata are leaving the local system and becoming subject to Apify's logging, retention, and terms.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.