Back to skill

Security audit

Instaparser

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward Instaparser API helper, with normal third-party processing and API-key risks users should understand.

Install only if you intend to use Instaparser. Set INSTAPARSER_API_KEY through your environment or a secure secrets feature instead of pasting it into chat, and avoid submitting private URLs, confidential article content, or sensitive PDFs unless you are comfortable with Instaparser processing them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill states it makes HTTPS requests to a third-party API but does not clearly warn that user-supplied URLs, article contents, and uploaded PDFs/files will be transmitted off-platform to Instaparser. This creates a real privacy and data-handling risk because users may provide sensitive documents or internal URLs without informed consent.

Missing User Warnings

Medium
Confidence
98% confidence
Finding
The instructions tell the agent to ask the user for their API key directly if the environment variable is not set, which encourages collection of credentials in conversation rather than using safer secret storage. This increases the risk of credential exposure through chat logs, tool traces, screenshots, or accidental reuse beyond the immediate request.

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal