Substack

Security checks across malware telemetry and agentic risk

Overview

This skill is purpose-built for Substack publishing, but it gives agents live editing and publishing authority with a long-lived session cookie and no clear confirmation boundary.

Install only if you are authorized to operate the Alternative Partners Substack. Store SUBSTACK_SID only in a secrets manager, review the local publisher code before use, and require an explicit preview plus approval that names the target post before any live publish or edit.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger text is overly broad and explicitly includes generic phrases like 'update the post' or 'edit that Substack', which can cause the skill to activate in ambiguous contexts. Because this skill performs real publishing actions against a live Substack, accidental invocation could modify or publish content without the user clearly intending to use this capability.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill advertises publishing and in-place editing of existing posts without an upfront warning that these operations can change live public content. In this context, the lack of a clear safety notice and confirmation boundary increases the risk of unintended edits, accidental publication, or silent modification of already-published material.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal