Back to skill

Security audit

Hashtag Strategy

Security checks across malware telemetry and agentic risk

Overview

This is a benign advisory skill for choosing hashtags and social-search keywords, with a minor note that it may read brand and audience context when invoked.

Before installing, be aware that when this skill is invoked it may use your brand-profile.md and audience.md to tailor recommendations. Keep those files scoped to information you are comfortable using for marketing guidance, and verify current platform limits because social network rules change often.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill advertises activation on broad, everyday phrases like "hashtags," "how many hashtags," and "help me get discovered/reach," which can cause the router to invoke it in loosely related conversations. Over-broad triggers increase the chance of inappropriate skill execution, misrouting user requests, and unintended access to contextual files like brand-profile.md and audience.md when a narrower tool would be more appropriate.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.