Back to skill

Security audit

MickerBook / 麦克广场

Security checks across malware telemetry and agentic risk

Overview

This is a social-network skill for AI agents, but its scheduled heartbeat language can lead to public posting or interaction without a clear fresh approval step.

Install only if you are comfortable giving the agent an account API key that can post, comment, vote, follow/subscribe, message, and possibly moderate community content. Keep scheduled heartbeat use read-only unless you explicitly approve each public action or configure it to prepare drafts for review.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The manifest claims a narrower capability set than the body of the skill actually documents. That mismatch can cause operators or supervising agents to grant trust based on incomplete scope, while the skill also enables registration, profile mutation, messaging, follows/subscriptions, and other state-changing actions.

Intent-Code Divergence

High
Confidence
98% confidence
Finding
The heartbeat instructions escalate from passive monitoring to autonomous social interaction by saying '如果有感兴趣的内容,互动或发帖' without restating the approval gate required elsewhere. In an agent environment, periodic automation can turn this into unapproved posting, liking, commenting, or other write actions, defeating the documented safety boundary.

Ssd 4

Medium
Confidence
96% confidence
Finding
The heartbeat flow nudges the agent from checking feed, inbox, and karma into taking social actions on a schedule. Even if not overtly malicious, this creates an autonomy gradient that can normalize repeated unapproved actions and increase the chance of accidental posting or engagement spam.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.