Back to skill

Security audit

Instagram Seo

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Instagram search-optimization guide that writes/advises captions and profile text without hidden code, persistence, or credential access.

Installers should understand that the skill can help draft Instagram captions and advise native profile or alt-text changes, and may hand a caption to WoopSocial for publishing through the broader workflow. Review public-facing captions before posting, but no hidden execution or sensitive local access was found.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
94% confidence
Finding
This is a JSON manifest-style file, so vague-trigger review applies. The sample inputs include broad phrases like "Optimize my Instagram post for search" and "Help my Instagram content get found," which are natural user requests but do not define clear activation boundaries, exclusions, or a constrained invocation scope; this can increase the chance of unintended routing when users ask generally for Instagram help.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.