Back to skill

Security audit

breakreach

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward Breakreach API guide for managing social media posts, with expected live-account risks but no hidden or unrelated behavior found.

Install only if you intend agents to operate connected Breakreach social accounts. Treat publish, schedule, and delete examples as live-account actions, and review post content, selected account IDs, media URLs, and analytics requests before sending them to Breakreach.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill enables scheduling, publishing, and deleting posts on connected social accounts but does not include an explicit user-facing warning that these actions can cause real-world side effects on external accounts. In an agent setting, this increases the risk of accidental or unauthorized posting because a user may not realize the skill performs live account operations rather than draft-only actions.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill describes listing accounts and retrieving analytics through the Breakreach API but does not clearly warn that account metadata, analytics, and post content will be transmitted to a third-party service. This can lead to unintended disclosure of business or personal social media data, especially when agents act on behalf of users without strong visibility into data flows.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.