social-media-viral-title-generator

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only skill for generating social media title ideas, with no code execution, credential use, persistence, or hidden system access.

This skill is reasonable to install where viral/social title generation is desired. Be aware that generic triggers like /generate-title may activate for broader writing tasks, and treat CTR scores as marketing heuristics rather than verified performance predictions. Review generated titles for accuracy, platform rules, and clickbait risk before using them publicly.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger keyword '/generate-title' is overly generic and can match many unrelated title-generation requests, causing this skill to activate outside its intended social-media viral-title scope. In an agent ecosystem, broad triggers can lead to unintended routing, prompt collisions, and execution of the wrong skill, which may degrade safety controls or produce inappropriate outputs for user intent.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger '/post-title' is ambiguous because 'post' can refer to social posts, blog posts, forum posts, job posts, or CMS content, making accidental activation likely. This ambiguity increases the chance of misrouting user requests to this skill, which can cause incorrect behavior and interfere with more appropriate, narrower skills.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger keyword '/generate-title' is overly generic and can easily match unrelated title-generation requests from other skills or normal agent interactions. In an agent environment with multiple installed skills, this can cause unintended invocation, routing confusion, or skill hijacking where this skill handles prompts outside its intended social-media viral-title scope.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger keyword '/post-title' is ambiguous because 'post' can refer to many contexts beyond social media, including blog posts, forum posts, CMS content, or generic writing tasks. This broad matching increases the chance of accidental activation and misrouting, which is especially risky in agent systems where skills may process user data or override more appropriate workflows.

VirusTotal

55/55 vendors flagged this skill as clean.

View on VirusTotal