Back to skill

Security audit

Social Media Content Planner

Security checks across malware telemetry and agentic risk

Overview

The skill appears intended for legitimate client planning work, but it tells agents to put client data in third-party tools and make the main spreadsheet editable by anyone with the link.

Review before installing. Use only private, account-restricted Google Sheets permissions, avoid anyone-with-link edit access, confirm Slack destinations before sending client summaries, and make sure client or company policy permits storing this planning data in Google and collaboration tools.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The README describes Google Sheets and Slack integration, but it does not prominently warn users that client data will be written to third-party services and may be shared into team communication channels during approval loops. In a skill that handles brand, audience, and planning details for clients, this omission can lead to unintended disclosure of confidential business information or personal data through misconfigured sheets or Slack destinations.

Missing User Warnings

Medium
Confidence
98% confidence
Finding
The skill explicitly instructs the agent to share the spreadsheet with edit access to anyone who has the link, which exposes onboarding answers, strategy notes, competitor lists, and calendar plans to unauthorized parties if the URL is leaked or forwarded. Because the sheet is the system of record and is reused monthly, the exposure can persist and compound over time, and edit access also enables tampering in addition to disclosure.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill directs use of Google Sheets, YouTube Data API, and Slack or similar messaging surfaces for handling client research and onboarding data, but it does not clearly warn users that client information and research artifacts may be disclosed to third-party services. This creates a real privacy and compliance risk, especially if client materials include sensitive business information, transcripts, or unpublished strategy data.

Ssd 3

Medium
Confidence
99% confidence
Finding
Instructing the spreadsheet to be shared with edit access to anyone with the link is a direct insecure-default access control issue. Anyone obtaining the URL can read, modify, or delete the client's planning data, making this both a confidentiality and integrity problem rather than a mere collaboration convenience.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.