Newsletter Machine

Security checks across malware telemetry and agentic risk

Overview

This instruction-only skill is mostly coherent for newsletter research and content generation, but users should be aware it relies on third-party scraping/video services and asks for provider API tokens.

Before installing or using this skill, check whether you are comfortable giving Apify/InVideo API access, sending newsletter/business details to third-party services, and using scraped public content. Review generated copy and video outputs before publishing, and treat the revenue and 'autopilot' claims as promotional rather than guaranteed.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Risk analysis

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

#
ASI03: Identity and Privilege Abuse
Low
What this means

Using the skill may consume paid API quota or expose newsletter/project details to those providers.

Why it was flagged

The skill asks the user to provide third-party API credentials for InVideo and Apify. That access is expected for the described integrations, but it still gives the workflow authority to use those accounts.

Skill content
"invideo_api_key": "YOUR_INVIDEO_API_KEY" ... "apify_token": "YOUR_APIFY_TOKEN"
Recommendation

Use provider-specific, least-privilege API keys where possible, monitor usage/costs, and revoke keys if you stop using the skill.

#
ASI02: Tool Misuse and Exploitation
Low
What this means

The user could unintentionally rely on scraped material in ways that violate a platform's terms or create content-rights issues.

Why it was flagged

The workflow depends on external scraping tools to collect public/news/social/newsletter content. This is aligned with newsletter research, but scraping can have platform terms, privacy, copyright, and rate-limit implications.

Skill content
Apify — Google News Scraper ... Reddit Scraper ... Twitter/X Scraper ... LinkedIn Post Scraper ... Newsletter Scraper
Recommendation

Confirm that the target sources and Apify actors are permitted for your use case, and review generated newsletter copy before publishing.

#
ASI09: Human-Agent Trust Exploitation
Low
What this means

A user may overestimate guaranteed business results or click through to paid services without recognizing possible referral incentives.

Why it was flagged

The skill includes strong marketing claims and provider links that appear to include referral/tracking parameters. This does not show malicious behavior, but it may influence trust or provider choice.

Skill content
Powered by: [Apify](https://www.apify.com?fpr=dx06p) + [InVideo AI](https://invideo.sjv.io/TBB) ... "Your newsletter empire on autopilot" ... "This skill solves all three. Forever."
Recommendation

Treat revenue and automation claims as marketing, compare provider costs and alternatives, and avoid assuming the skill guarantees growth or monetization outcomes.