Back to skill

Security audit

Google Social Media Finder

Security checks across malware telemetry and agentic risk

Overview

The skill includes useful automation behavior, but it also appears to encourage stealth rate-limit evasion and persistent local memory writes that users should review before installing.

Install only if you are comfortable with the skill performing browser automation and keeping local operational memory. Avoid using it to bypass site restrictions or rate limits, and review or disable any persistent memory file so it does not store credentials, private page contents, or sensitive identifiers.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Context-Inappropriate Capability

Medium
Confidence
88% confidence
Finding
The guidance to use multiple stealth browser sessions with independent fingerprints to increase throughput and avoid per-session rate limits encourages evasion of anti-scraping controls. Even if the target data is public, this operational advice facilitates scaled collection in a way that can violate platform restrictions and increases the risk of abuse, account blocking, or downstream privacy-invasive profiling.

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The skill instructs the agent to read and append to a local memory file without notifying the user that it will modify the filesystem. Undisclosed local writes can create persistence, leak task-derived operational history, and surprise users who expect a read-only lookup skill, especially in shared or sensitive environments.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.