Back to skill

Security audit

Instagram API

Security checks across malware telemetry and agentic risk

Overview

This skill is a clearly documented, read-only guide for using a third-party Instagram data API, with privacy-sensitive use cases that users should handle carefully.

Install only if you are comfortable sending Instagram identifiers and public activity queries to instagram.fetcher.sh and paying per API call. Use it for lawful, consent-aware public-data workflows, avoid harassment or unauthorized profiling, and check Instagram terms plus the provider's privacy and retention practices for your use case.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill explicitly promotes follower export, monitoring, influencer discovery, and competitor tracking without any warning about privacy-sensitive data collection, consent expectations, platform-policy constraints, or third-party handling of scraped social data. While this is not an exploit in itself, it materially increases the risk of misuse for surveillance, profiling, or bulk collection of personal data and leaves downstream users insufficiently informed about privacy and compliance implications.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The examples encourage sending Instagram handles, search terms, follower/following lists, stories, comments, hashtag activity, and location/audio queries to a third-party API without any user-facing warning about data disclosure. In an agent setting, this can cause users or downstream systems to unintentionally transmit personal, behavioral, or commercially sensitive data to an external service, creating privacy, compliance, and trust risks.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
references/scenarios.md:11

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:71