Crypto Content Automation

Security checks across malware telemetry and agentic risk

Overview

This skill is not clearly malicious, but it needs review because it advertises cookie-based social posting and its runner can execute unreviewed local helper code from a hard-coded workspace path.

Review before installing. Do not provide Xiaohongshu or Binance Square cookies unless you know exactly where they will be stored and used, and require manual approval before any post is published. Also verify or replace the missing helper modules because the bundled runner may execute code from a local workspace path that was not reviewed with this package.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly supports posting to external platforms using cookies but does not provide any security guidance on how those credentials should be stored, scoped, or protected. In a crypto-related publishing tool, stolen or mishandled cookies could enable account takeover, unauthorized posting, reputational damage, and exposure of linked personal or financial platform data.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal