Back to skill

Security audit

Mia Content Creator

Security checks across malware telemetry and agentic risk

Overview

This appears to be a local content-template tool that saves generated post history, not a hidden social-media posting or monetization system.

Install it only if you want a local draft/content-template CLI. Expect it to create or update content-log.json in whatever directory you run it from, and do not assume it actually posts to Moltbook or Twitter/X or tracks real revenue unless future reviewed code adds those capabilities.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
83% confidence
Finding
The usage and feature descriptions are broad and do not define clear activation boundaries, consent requirements, or limits for automated content generation and posting. In an agent skill that can schedule posts across platforms, vague scope increases the chance of unintended autonomous actions, spammy behavior, or operation against the wrong account or context.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill advertises automated posting and analytics but does not warn users about account impact, data collection, retention, or privacy implications. Because this skill operates on social platforms and tracks engagement, missing disclosures can lead users to unknowingly expose account metadata, posting behavior, or audience analytics to the tool.

Vague Triggers

Low
Confidence
79% confidence
Finding
The skill description is broad and does not clearly constrain when the agent should activate or what user authorization is required before acting. In a skill that can generate, schedule, and potentially publish content to external platforms, ambiguous scope can cause unintended invocation or overbroad autonomous actions affecting real accounts.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The usage section describes content creation, scheduling, and analytics for external platforms without warning users that these actions may post to third-party accounts, process engagement data, or affect account reputation and monetization. Missing disclosure increases the risk of users triggering automated actions without understanding the consequences for their external accounts and associated data.

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.