Back to skill

Security audit

Link In Bio And Traffic

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed marketing strategy skill for social traffic and link placement, with no hidden code, install hooks, persistence, or credential handling.

Before installing, treat the platform-specific placement table as marketing guidance that may need validation against current platform behavior, especially for X. The skill is otherwise a documentation-only strategy aid and should be used with human review before publishing posts or relying on analytics.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
The document instructs users to place links in an X 'first comment,' but X does not have a comment model equivalent to other platforms, so the tactic is operationally impossible. In a marketing/traffic skill, this can mislead automation or human operators into publishing broken or nonfunctional CTAs, reducing campaign effectiveness and causing inaccurate execution against platform-specific constraints.

Intent-Code Divergence

Medium
Confidence
98% confidence
Finding
The worked example reinforces the same invalid X tactic, making it more likely that users or agents will operationalize a nonexistent 'first comment' placement. Because this file is prescriptive guidance for traffic generation, the bad instruction is especially dangerous in context: it can systematically produce unusable publishing behavior and undermine trust in analytics and conversion strategy.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.