Back to skill

Security audit

PostNext Social Manager

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed PostNext social media helper whose sensitive powers are expected for publishing workflows, but users should approve posts and deletions carefully.

Install only if you trust PostNext with the connected social accounts and keep the API key private. Review generated content before publish or schedule actions, and require clear user approval before deleting posts or assets because those operations can remove account content from PostNext.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Tool Parameter Abuse

High
Category
Tool Misuse
Content
- `GET /api/assets/mine?page=1&limit=50` -> `{success, data, pagination}` (pagination is top-level).
- `GET /api/assets/{assetId}` -> `{success, data}`.
- `DELETE /api/assets/{assetId}` -> flat `{message, success}`.
Confidence
84% confidence
Finding
DELETE /api/assets/{assetId}`

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.