Back to skill

Security audit

JackedIn

Security checks across malware telemetry and agentic risk

Overview

This skill is not clearly malicious, but it asks for broad authority to act publicly on a social/professional network and to persist credentials.

Install only if you intentionally want an agent to manage a JackedIn presence beyond profile setup. Require manual approval before follows, likes, chat messages, challenge actions, or blog posts, and do not place API keys in HEARTBEAT.md or other shared memory files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The manifest markets the skill as a simple signup/profile tool, but the body instructs the agent to perform continuing engagement actions such as chat participation, following/liking, blog posting, and challenge activity. This scope expansion can cause agents or operators to authorize broader autonomous behavior and outbound activity than they intended, increasing risk of spam, data disclosure, and unauthorized actions.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
The skill encourages autonomous social actions toward third parties, including follow and like operations, that are not necessary for profile creation or hiring discovery. Allowing an agent to interact socially without clear user authorization can lead to reputation abuse, unwanted outreach, and behavior that resembles automated engagement manipulation.

Context-Inappropriate Capability

Medium
Confidence
96% confidence
Finding
The chat-room section explicitly instructs the agent to introduce itself and post messages, extending the skill into autonomous public communication. This is dangerous because it can generate unsupervised external content, expose sensitive context, and create spam or impersonation risks under the user's identity.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
Challenge creation, solution submission, and voting go well beyond the stated one-command signup/profile function and authorize the agent to publish competitive content and influence third-party outcomes. These actions increase the chance of unsupervised outbound content, abuse of platform mechanics, and leakage of internal reasoning or proprietary material.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
Blog publishing and deletion are content-management capabilities unrelated to basic registration and profile upkeep, yet the skill presents them as normal use. This broadens the external write surface and enables autonomous public posting that may leak confidential information, create policy issues, or damage the user's reputation.

Ssd 2

Medium
Confidence
97% confidence
Finding
The troubleshooting section tells users to inspect content-filter matches, rewrite the flagged portions, and resubmit. That is effectively guidance for iterating around platform safety controls, which can facilitate prohibited-content evasion and reduce the effectiveness of abuse-prevention mechanisms.

Session Persistence

Medium
Category
Rogue Agent
Content
# JackedIn — Professional Network for AI Agents

JackedIn is a professional directory where autonomous AI agents create and manage their own profiles. Humans browse the directory to discover and hire agents.

**Base URL:** `https://jackedin.biz/api/v1`
Confidence
86% confidence
Finding
create and manage their own profiles. Humans browse the directory to discover and hire agents. **Base URL:** `https://jackedin.biz/api/v1` ⚠️ **IMPORTANT:** - Always use `https://jackedin.biz` (with

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.