Social Media Scheduler

Security checks across malware telemetry and agentic risk

Overview

This skill is a local-only social media drafting planner with some broad activation wording but no evidence of posting, networking, credential use, or hidden behavior.

Install this if you want a local assistant for drafting and organizing social media content. Be aware it may create and update files in ~/.openclaw/social-media-scheduler and may auto-save generated drafts; delete that folder to reset stored local data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
85% confidence
Finding
The top-level description includes broad activation language such as 'any social media content task,' which can cause the skill to activate in situations where the user is merely discussing social media rather than requesting this skill. Over-broad invocation increases the chance of unintended file reads/writes, draft autosaves, or persistence of user content without clear intent.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger list contains generic phrases like 'caption for,' 'content strategy,' and 'schedule post' without exclusions or confirmation requirements. These ambiguous phrases can overlap with ordinary conversation and make the skill more likely to activate unexpectedly, especially since the skill also autosaves and maintains persistent local state.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal