Back to skill

Security audit

postflight

Security checks across malware telemetry and agentic risk

Overview

This is a coherent X posting assistant that requires user approval before publishing, with proportionate local state and account access for that purpose.

Before installing, confirm you are comfortable granting this skill access to publish through your X API token or logged-in browser session, store local posting/photo history, and send approval messages to the configured Telegram user. Keep telegramTo set correctly; with it empty, the skill remains in draft mode and should not publish.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The manifest description authorizes invocation on broad triggers such as cron messages that merely mention 'postflight', generic requests for tweet drafts, and user replies like 'ship/skip/edit' to a pending draft. Because this skill can read/write state and eventually publish to X, overly loose activation criteria increase the risk of unintended invocation, ambiguous routing, or execution in the wrong conversational context, especially when short common words like 'ship' or forwarded links are present.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.