X Post

Security checks across malware telemetry and agentic risk

Overview

This is a simple drafting helper that openly saves X post drafts and journal links in an Obsidian vault.

Install this only if you want the agent to create draft files in your Obsidian vault and add links to your daily journal. Before first use, tell the agent the exact vault and journal location, and ask for a preview first if you do not want files changed automatically.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs the agent to save content into the vault and always add a link to today's journal, but it does not clearly warn that using the skill will modify user files. That can lead to unexpected writes, journal pollution, or persistence of sensitive/generated content when a user only intended to brainstorm copy, especially because the skill is user-invocable and framed as a drafting tool.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal