Back to skill

Security audit

Phy Twitter X Gtm

Security checks across malware telemetry and agentic risk

Overview

This is a text-only Twitter/X marketing strategy skill that researches public content and drafts posts, with no code, credentials, persistence, or automatic posting behavior.

Install this as a drafting and strategy helper, not as a posting tool. Review all generated tweets before publishing, avoid sharing confidential business or customer information, and confirm the desired output language when drafting for a multilingual audience.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger description is overly broad and can cause the skill to activate for generic Twitter/X marketing planning rather than narrowly scoped founder/DTC/investor strategy use cases. Overbroad activation increases the chance of inappropriate routing, user confusion, and unintended application of a prescriptive marketing persona in contexts where it may be irrelevant or misleading.

Natural-Language Policy Violations

Medium
Confidence
82% confidence
Finding
The examples show non-English user inputs receiving English outputs without first confirming the user's preferred language. This can lead to poor user experience, incorrect audience targeting, and accidental generation in the wrong language for downstream posting or review workflows.

VirusTotal

No VirusTotal findings

View on VirusTotal

Static analysis

No suspicious patterns detected.