Back to skill

Security audit

postfast

Security checks across malware telemetry and agentic risk

Overview

This skill is coherent for PostFast social media management, but it gives agents live posting and moderation powers including irreversible comment deletion without requiring explicit confirmation.

Install only if you trust PostFast with the connected accounts and media you manage. Before use, configure the agent or operator workflow to ask for explicit approval before deleting comments, deleting scheduled posts, sending replies, private-replying, or posting publicly; prefer drafts, pending approval, hide, or snooze when intent is uncertain.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill exposes destructive moderation actions such as HIDE, UNHIDE, and especially DELETE on live platform comments, but the agent guidance does not require explicit user confirmation before taking irreversible actions. In an agent setting, ambiguous user requests, prompt injection through comment content, or simple operator error could cause unintended deletion or moderation of third-party content across connected social accounts.

VirusTotal

57/57 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.