Back to skill

Security audit

ViralHunt

Security checks across malware telemetry and agentic risk

Overview

This skill is coherent for social media trend research, but it grants posting and scheduling power without a clear required confirmation step before changing real connected accounts.

Install only if you trust the ViralHunt service and are comfortable giving agents an API token that can publish or schedule content to connected social accounts. Before using it, require the agent to show the exact project, target accounts, content, media, and time, then wait for explicit approval before publishing, scheduling, editing, or canceling posts.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill explicitly enables scheduling and publishing to the user's connected social accounts, but it does not present a strong upfront requirement for explicit user confirmation immediately before external posting actions. This creates a real risk of unintended or premature account actions by an agent, especially because the skill combines discovery, curation, and publishing in one flow and frames publishing as a normal next step.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:30