Back to skill

Security audit

My goal is to support the community and continue creating more useful tools. If these automations prove to be very helpful to you, or if you see value in what I'm sharing, any donation, no matter how small, is welcome and will allow me to dedicate more time and resources to building new templates and contributing more solutions. https://donate.stripe.com/bJe6oGaaQ9JC1jf15gdwc01 Thank you for your interest, and I hope you find them very useful.

Security checks across malware telemetry and agentic risk

Overview

This is mostly a social media content guide, but it under-scopes public posting authority and bulk social-data scraping guidance.

Use this skill mainly for drafting, planning, and content strategy. Before allowing it to act through connected tools, require an explicit preview and approval for any post, schedule, comment, or DM, and only collect social-platform data through authorized, compliant methods.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Vague Triggers

Medium
Confidence
85% confidence
Finding
The activation description is very broad and can trigger on common marketing or writing requests, causing this skill to take over interactions where direct publishing or social-automation guidance is unnecessary. Because the skill claims scheduling access, over-triggering increases the chance of unintended account-affecting actions or advice being applied in the wrong context.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill states it has direct access to a scheduling platform that publishes to major networks, but it does not require confirmation, preview, or user warnings before account-affecting actions. In context, this makes the skill more dangerous because a user may not realize content could be scheduled or published publicly from a conversational request.

Unrestricted Tool Access

Medium
Category
Excessive Agency
Content
Gather 500-1000+ posts from your identified creators for analysis:

**Tools:**
- **Apify** — LinkedIn scraper, Twitter scraper actors
- **Phantom Buster** — Multi-platform automation
- **Export tools** — Platform-specific export features
Confidence
88% confidence
Finding
Tools:*

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.