Dataify Instagram Comment By Posturl

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Dataify connector for submitting Instagram comment collection tasks, with token use and external submission aligned to its stated purpose.

Before installing, understand that this can use a saved Dataify API TOKEN to create paid or quota-consuming Dataify scraping tasks. Review the parameters shown before approval, avoid saving the token if you do not want reuse, and ensure your Instagram comment collection complies with Dataify, Instagram, and applicable privacy rules.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger text is broad and includes phrases like 'or similar' and troubleshooting/token-handling cases, which can cause the skill to activate for loosely related requests. Because the skill can access a saved token and submit external jobs, unintended invocation materially increases the chance of unauthorized or surprising actions.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill enables implicit invocation without any visible, narrowly scoped activation guard in this file. Because the skill can submit external Dataify tasks for Instagram comment collection, broad auto-invocation increases the chance of unintended triggering, over-collection, or abuse from ambiguous user prompts, causing external actions without sufficiently explicit user intent.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal