Publora Instagram

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a normal Publora Instagram posting helper that uses expected API calls, with the main caution being that posting and media upload send user content to Publora and upload endpoints.

Install only if you trust Publora with the Instagram account connected to your API key. Before posting or uploading, confirm the destination account, caption, media, schedule, and whether the content contains private or sensitive information.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill includes concrete examples that send captions, platform identifiers, API keys, and media-upload metadata to Publora and then to a presigned external upload destination, but it does not explicitly warn that user content and account-linked data will be transmitted off-platform. In a posting skill this transmission is expected, yet the lack of an explicit disclosure/consent reminder can cause unintended disclosure of sensitive content or use of the wrong connected account.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal