Facebook Graph API Skill (Secure)

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only Facebook Page API skill with sensitive but expected credentials and disclosed posting/moderation actions.

Install this only if you intend to manage Facebook Page content through Graph API credentials. Store tokens and app secrets in a secure secret manager, use the narrowest Page permissions possible, and require explicit human approval before publishing, editing, hiding, or deleting Page content.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The template documents destructive moderation actions such as hiding and deleting comments without any caution, confirmation guidance, or role/permission warning. In an agent skill that automates Facebook Page workflows, this can normalize unsafe use and increase the chance of accidental or overbroad moderation actions that affect user content and Page reputation.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal