Back to skill

Security audit

collabs-and-cross-promotion

Security checks across malware telemetry and agentic risk

Overview

This documentation-only skill plans creator collaborations and clearly limits WoopSocial to scheduling each partner’s own posts, with some guidance needed around giveaways and native platform features.

Before installing, understand that this skill can help plan and draft collaboration content, including giveaway-style campaigns, but users should manually verify platform rules, legal requirements, disclosures, and any native collab or giveaway mechanics before publishing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The reference content recommends formats the skill metadata explicitly says are not supported, including joint giveaways and native YouTube Collaboration-style joint uploads. This can cause an agent using the reference to generate instructions or plans that exceed platform/tool capabilities, creating unsafe or noncompliant user guidance and increasing the chance of policy violations around promotions and disclosures.

Intent-Code Divergence

High
Confidence
99% confidence
Finding
The worked example states that WoopSocial can publish giveaway posts, directly conflicting with the skill description that it does not run giveaways. Because examples are highly influential in agent behavior, this contradiction may prompt the agent to operationalize or encourage giveaway campaigns under false assumptions about support, which can lead to policy, disclosure, and user-trust failures.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The reference file instructs or endorses native platform collab features and joint giveaways, while the skill manifest explicitly states this skill does not perform those actions. That mismatch can cause an agent to recommend or attempt unsupported workflows, creating policy drift, user deception, or accidental non-compliant campaign guidance.

VirusTotal

45/45 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.