Instagram Photo Find

Security checks across malware telemetry and agentic risk

Overview

This instruction-only skill is purpose-aligned and disclosed: it searches public Instagram posts, downloads candidate images to /tmp for scoring, and shows no hidden code or credential use.

Reasonable to install if you want an agent helper for finding public Instagram destination photos. Be aware it may download untrusted public images into /tmp and send them to a vision model for scoring; delete temporary files afterward if you do not want them retained, and use it only for content you are comfortable fetching and processing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The workflow instructs the agent to fetch arbitrary external content and write it to local storage under /tmp without explicit user consent or clear safety constraints. Even though /tmp is transient, downloading attacker-controlled files can enable disk consumption, unsafe downstream processing, or exposure to malformed content from untrusted origins, making this a genuine security concern in an automated agent context.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal