PigBun RedNote

Security checks across malware telemetry and agentic risk

Overview

This skill is coherent for RedNote automation, but it gives broad live control over a social account without enough safety and credential-handling detail.

Review before installing. Use a test or low-value RedNote account first, verify the publisher and pigbunai.com, keep the API key out of shared files or chats, and do not allow publish, delete, edit, comment, follow, or collect actions unless you can confirm they require explicit per-action approval.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill advertises account-affecting and destructive actions such as publishing, editing, deleting notes, commenting, following, and interacting on behalf of the user, but provides no warning, confirmation, or consent boundaries. In an agent context, this increases the risk of unintended posts, deletions, spammy behavior, or irreversible account actions triggered by ambiguous prompts or automation errors.

Missing User Warnings

Low
Confidence
81% confidence
Finding
The documentation shows how to place a live API key directly into configuration but does not include any warning about secret handling, storage hygiene, rotation, or avoiding accidental disclosure. While this alone is not an exploit, it materially increases the chance that users will mishandle credentials in logs, screenshots, repositories, or shared config files.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal