Back to skill

Security audit

SocQ Instagram Research

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed SocQ integration for collecting public Instagram research data, with credential and cost guardrails but limited privacy-use guidance.

Install only if you intend to use SocQ for public Instagram research and are comfortable sending scoped requests to SocQ with a credit-metered API key. Set clear limits on accounts, hashtags, dates, and result counts, avoid unnecessary follower/comment/transcript collection, and follow applicable platform terms, privacy rules, and retention expectations for any exported data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
85% confidence
Finding
The file documents capabilities to collect public Instagram profile metadata, follower/following lists, comments, and transcripts, but provides no warning about privacy, data minimization, consent, retention, or legal/compliance constraints. Even when data is public, these endpoints enable bulk aggregation and profiling, which can materially increase privacy risk and make downstream misuse easier in an agentic setting.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.