Instagram Page

Security checks across malware telemetry and agentic risk

Overview

This Instagram management skill appears coherent and non-malicious, but it gives an agent comment-deletion authority without an explicit confirmation safeguard.

Install only if you are comfortable giving the agent access to your Instagram Business/Creator account via Meta credentials. Before using moderation features, require the agent to show the exact comment ID/text and get your explicit confirmation before any delete request; prefer hiding or reviewing comments first when possible.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
79% confidence
Finding
The skill explicitly includes a destructive `DELETE` operation for Instagram comments but does not require a confirmation step or clearly warn that deletion is irreversible. In an agentic context, that increases the risk of accidental moderation actions from ambiguous user prompts or model misinterpretation, leading to unintended loss of user content and possible account-management harm.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal