Back to skill

Security audit

SocQ Social and SEO Research

Security checks across malware telemetry and agentic risk

Overview

The skill is a coherent SocQ integration for public social and SEO research, but users should treat it as a third-party data-collection tool and apply privacy limits.

Install only if you are comfortable sending requested URLs, usernames, keywords, domains, and returned public social data to SocQ. Use it for lawful, authorized research, set result limits, avoid sensitive personal targeting or harassment use cases, and check credit costs before broad or cross-platform runs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The catalog exposes a very broad set of capabilities for collecting public social-media profiles, posts, comments, follower/following graphs, and transcripts across many platforms, but provides no accompanying privacy, acceptable-use, retention, or consent guidance. While the file is descriptive rather than executable, this omission can enable misuse by downstream agents or users who may treat large-scale people-data collection as routine and unconstrained.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
This file documents multiple SocQ Facebook endpoints and example inputs, but it does not warn users that supplied Facebook URLs, usernames, queries, and identifiers will be transmitted to an external third-party service. That omission can cause unintentional disclosure of sensitive investigation targets, internal research interests, or personal data, especially in enterprise or regulated environments where users may assume processing is local.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The file documents endpoints that enable collection of public Instagram profile metadata, follower/following lists, comments, and transcripts, but it provides no privacy warning, use restrictions, or caution about sensitive aggregation of public data. While the data may be publicly accessible, packaging these capabilities into easy-to-use research tools increases the risk of mass profiling, monitoring, or harassment if users are not clearly warned about privacy-sensitive use.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The file documents SEO endpoints and example inputs but does not warn that user-supplied queries, keywords, and target domains will be transmitted to an external SocQ service. This creates a real privacy and data-handling risk because operators may unknowingly send sensitive research terms, internal domains, or client data to a third party.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The file documents multiple endpoints for collecting public X profiles, followers, replies, retweeters, and search results, but provides no warning that user inputs and retrieved records are sent to an external service or may contain personal data. In an agentic context, this omission can lead to silent bulk collection and transmission of social-platform data without informed user consent, increasing privacy, compliance, and misuse risk.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.