Back to skill

Security audit

XReplyAI - Social Post Manager

Security checks across malware telemetry and agentic risk

Overview

This skill is a clearly disclosed social-media posting tool, but users should treat publish and delete actions as live account actions that need explicit confirmation.

Install only if you intend to let your agent manage connected XreplyAI social accounts. Require explicit approval before any xreply_posts_publish call without scheduled_at, before deleting posts or rules, and before uploading local media files. Be aware that connected account details and billing/quota data may be read through the XreplyAI API.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill exposes a publish operation that can post immediately to external social platforms if `scheduled_at` is omitted, but the documentation does not prominently warn about that side effect at the point of use. In agentic contexts, a model may invoke the tool based on an ambiguous user request, causing unintended public posting, reputational harm, or disclosure of sensitive draft content.

Missing User Warnings

Low
Confidence
90% confidence
Finding
The skill includes a delete operation for posts without clearly emphasizing that deletion is destructive and may be irreversible. In an agent workflow, this increases the chance of accidental removal of drafts or scheduled content due to misunderstanding or over-broad user instructions.

Vague Triggers

Low
Confidence
86% confidence
Finding
The manifest exposes a broadly capable social-media publishing skill but does not define any activation conditions, trigger constraints, or other metadata that would limit when the agent should invoke it. In an agent ecosystem, this can cause over-broad or unintended activation for posting, scheduling, billing, or preference-management actions, increasing the chance of accidental misuse of high-impact capabilities.

VirusTotal

58/58 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.