Threads Skills

Security checks across malware telemetry and agentic risk

Overview

This Threads automation skill appears purpose-aligned, but it can affect a live social account and its trigger/language controls are too broad for that authority.

Install only if you intentionally want Threads account automation. Before using it, confirm each public post, reply, follow, bulk action, login change, or cookie deletion, and check that generated content uses the language and wording you actually intend.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger list contains very broad natural-language phrases such as everyday actions and generic verbs, which can cause the skill to activate when the user did not intend to invoke high-risk browser automation. In this skill, unintended invocation is especially dangerous because the available actions include login state changes, posting, following, replying, bulk interaction, and cookie deletion on a real social-media account.

Natural-Language Policy Violations

Medium
Confidence
86% confidence
Finding
Mandating that all AI-generated content be in Traditional Chinese without user opt-in overrides user intent and can silently alter output semantics, audience targeting, or compliance expectations. In this skill, that matters more because the tool performs autonomous posting and replies on a live social platform, so the language policy can cause unintended public actions or miscommunication at scale.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal