Back to skill

Security audit

Threads Post

Security checks across malware telemetry and agentic risk

Overview

This skill is a scoped Threads post-writing and WoopSocial publishing helper with disclosed limits and no hidden execution behavior.

Before installing, understand that this skill is meant to help draft and publish or schedule a single public Threads post through WoopSocial. Review the generated post before publishing, especially links, media, brand claims, and timing; use separate community-management or analytics workflows for replies and performance review.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The manifest states this skill should treat WoopSocial publishing as supporting one Threads post with no polls, voice, or GIFs. This reference file says Threads supports polls, GIFs, and voice notes, which can directly mislead the skill logic or prompt instructions about what the skill can publish.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The description says to use this skill when someone wants to "grow on Meta's Threads," which is broader than writing and publishing a single Threads post. That phrase could overlap with general strategy, analytics, or community-management requests and may cause unintended invocation despite later sibling distinctions.

VirusTotal

VirusTotal engine telemetry is currently stale for this artifact.

View on VirusTotal

Static analysis

No suspicious patterns detected.