Back to skill

Security audit

Mixpost

Security checks across malware telemetry and agentic risk

Overview

This is a transparent Mixpost API helper, but it can create, publish, schedule, upload, update, and delete social media content if given a powerful token.

Install this only if you want an agent to manage your Mixpost workspace. Use the least-privileged token available, confirm the workspace UUID, keep the token out of logs and shared files, and require explicit confirmation before publishing, scheduling, approving, uploading, updating, or deleting posts or media.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill documents delete endpoints, including bulk deletion and cross-platform deletion modes such as `app_and_social` and `social_only`, without any caution that these actions may be irreversible or affect live social media content. In an agent context, this omission increases the chance that an automated system or user will invoke destructive operations without understanding the blast radius, leading to unintended loss of posts across Mixpost and connected social accounts.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.