GetPost SMS API

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only SMS API skill that clearly documents SMS sending and inbox access, with privacy and consent cautions but no hidden or executable behavior.

Install only if you trust GetPost and intend to let an agent use your SMS account. Keep the API key private, require explicit approval for recipients, message content, number provisioning, and webhook registration, and treat phone numbers and SMS contents as sensitive data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill documents the ability to send and receive SMS messages, including inbox access and webhook-driven receipt handling, but provides no guidance on user consent, lawful use, retention, or protection of message contents and phone numbers. In an agent context, this can enable privacy violations, unauthorized messaging, and handling of sensitive communications without clear safeguards.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal