Boring Social Media Publisher

Security checks across malware telemetry and agentic risk

Overview

The skill appears to perform expected media-upload behavior for its service, but users should understand that selected local files may be sent to Boring’s cloud.

Install only if you are comfortable with chosen local media files being transmitted to Boring’s cloud service and potentially stored or hosted there. Avoid uploading private or sensitive files unless you trust the service and have checked its retention and sharing behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly instructs the agent to upload local files via `boring_upload_file` to a third-party service, but it does not require an explicit user warning or confirmation that the local media will leave the device and be hosted remotely. This creates a real privacy and data-handling risk because users may assume a local attachment is only being used for posting, not transmitted to and stored by an external provider.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal