Back to skill

Security audit

Crebee Agent Skill V1.9.9

Security checks across malware telemetry and agentic risk

Overview

This skill is coherent, but it can publish to real social media accounts and read account/audience data without strong confirmation or privacy guardrails.

Review this before installing if you manage real brand, business, or personal accounts. Only use it with accounts you control, confirm every publish or cancellation request, keep the CreBee token private, and avoid requesting fan/audience/profile data unless it is needed for the current task.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill’s trigger conditions are very broad and overlap with many ordinary social-media requests, increasing the chance that an agent invokes it for actions the user did not clearly intend. Because this skill can access local authenticated accounts and perform high-impact operations such as publishing content or retrieving analytics, overbroad activation creates a real risk of unintended account actions and privacy exposure.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The documentation exposes capabilities for bulk publishing, account enumeration, analytics, and audience-profile access without clearly warning that these actions can affect live social-media accounts and process potentially sensitive personal or behavioral data. In an agent setting, missing user-facing warnings and consent expectations increases the likelihood of privacy-invasive access or accidental publication under legitimate stored credentials.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The document explicitly exposes an endpoint for retrieving fan profiling data, including demographic and interest information, but provides no guidance on authorization checks, user consent, data minimization, or handling restrictions. In an agent skill that automates social media operations, this omission increases the chance that downstream agents or integrators will treat sensitive audience analytics as routine data and access or redistribute it without adequate privacy controls.

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The documentation exposes authenticated analytics and profile-access endpoints for public-account data, including account identifiers, per-post performance metrics, and audience portrait information, but provides no warning or guardrails about authorization scope, least-privilege handling, or the sensitivity of profile/analytics data. In an agent skill that automates social-media management across accounts, this omission increases the risk that an agent or integrator will query or route sensitive account data for the wrong tenant or user without adequate consent checks.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
This documentation exposes account-scoped analytics and follower-portrait endpoints that process potentially sensitive creator and audience data, but it gives no privacy, consent, retention, or access-control guidance. In an automation skill that enables cross-platform social-media management, this omission increases the chance that an agent or integrator will collect or use profiling data without adequate safeguards or user awareness.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The publishing parameter docs instruct callers to provide local file paths and account-scoped publishing metadata, but they do not warn that these files and metadata may be uploaded to an external platform and published under a real account. In an agent skill designed for automated posting, this can lead to unintended disclosure of local content, accidental publication, or misuse of the wrong account/context if operators assume these are only local references.

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The documentation exposes authenticated endpoints that return account analytics, friend lists, locations, notifications, and user portrait data, but it does not instruct consumers to treat these responses as privacy-sensitive or to limit access, storage, and downstream use. In an automation skill that brokers multiple social-media accounts, this omission increases the risk of over-collection, unauthorized access, or accidental disclosure of personal and account-level data.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The publishing documentation describes parameters for immediate and scheduled posting to external social-media accounts, including public-facing content fields, but it does not warn that using these APIs can cause real-world state changes on behalf of a connected account. In an agent skill intended for automated social-media management, that omission is risky because users or downstream agents may invoke publishing actions without adequate confirmation, authorization checks, or understanding of the consequences.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.