Back to skill

Security audit

instagram-post-generator

Security checks across malware telemetry and agentic risk

Overview

This skill is a documented third-party Instagram post generation API wrapper, with expected use of an API key and user-provided prompts/images.

Install only if you are comfortable sending prompts, uploaded reference images, and design configuration to the DeepNLP/OneKey/Craftsman service. Store the API key as a secret, avoid pasting it into prompts or committed files, and treat generated share URLs as potentially accessible to others who receive the link.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The documentation instructs users to place a required access key in an environment variable and transmit it in requests, but provides no warnings about secret handling, logging, shell history exposure, CI leakage, or safe storage. In a skill context that relies on third-party API access, this increases the chance that credentials are mishandled, copied into prompts, committed to repositories, or exposed in shared terminals and automation.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.