Back to skill

Security audit

Instagram Growth

Security checks across malware telemetry and agentic risk

Overview

This is a plain Instagram strategy skill with disclosed, purpose-aligned use of brand and audience context and no executable or hidden behavior.

Before installing, be aware that the skill expects access to your brand, social strategy, audience notes, and Instagram Insights that you provide. It does not itself publish posts or access accounts, but any related publishing or scheduling skills it routes to should be reviewed separately.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
This is a JSON manifest-like file, so SQP-1 applies. The eval input uses the broad phrase "Help me grow," which is a common everyday expression and does not by itself narrowly scope the skill's activation context or provide exclusions, increasing the risk of unintended invocation if reused as a trigger description.

VirusTotal

55/55 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.