Back to skill

Security audit

Facebook Account Operations

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only Facebook Page operations skill with disclosed automation guardrails, but it should be used only for owned Page workflows.

Install only if you want an agent to assist with an owned Facebook Page. Keep it limited to Meta Business Suite Page inbox, comments, and moderation; require human approval for outbound comments on other Pages; protect the logged-in browser profile and alert webhooks; and add your own privacy rules for local logs, including retention, redaction, and restricted access.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill description is broad enough to be invoked for almost any Facebook-related automation task, including high-risk or out-of-scope actions. In this context, that increases the chance an agent will apply the doctrine to sensitive surfaces like personal profiles, third-party groups, or aggressive engagement flows despite the document's stated cautions, which can lead to platform-policy violations or unsafe automation decisions.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.