Content Distribution

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed multi-platform publishing helper, but users should confirm accounts and platforms before letting it post.

Install only if you intend to connect real publishing accounts. Before any distribute or schedule action, confirm the exact platforms, account identities, subreddit/community targets, timing, and final text, because mistakes may become public posts across multiple services.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill description is broad enough to match ordinary user requests about writing or sharing announcements, which increases the chance that an agent invokes a live-publishing workflow when the user only intended drafting help. Because this skill can route content to multiple external platforms using configured credentials, ambiguous invocation scope can lead to unintended real-world actions across several accounts at once.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill does not prominently warn that it can perform live publication to third-party platforms with preconfigured credentials, so users or agents may treat it like a drafting utility rather than an action-taking publisher. In this context, the omission is more dangerous because the MCP supports multi-channel posting, scheduling, and retries, which can amplify accidental or unauthorized publication across multiple public accounts.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal