Boring Social Analytics

Security checks across malware telemetry and agentic risk

Overview

This is a read-oriented social media analytics skill with disclosed Boring MCP credential use and no executable local code.

Install only if you trust Boring with analytics access to the connected social accounts. Treat the MCP URL like a password, avoid sharing it, regenerate it if exposed, and review Boring's account disconnection and data retention controls.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill advertises activation on vague, everyday phrases such as 'view stats' and a broad condition like wanting to see performance data, which can cause the agent to invoke this skill in contexts the user did not specifically intend. Because the skill exposes analytics across multiple connected social accounts and relies on an MCP URL containing embedded auth, accidental invocation can lead to unnecessary access and disclosure of sensitive performance data.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal