Back to skill

Security audit

Buymeacoffee Autobot

Security checks across malware telemetry and agentic risk

Overview

This skill is not overtly malicious, but it asks for account credentials and directs automated posting, messaging, promotion, and earnings scraping without clear safeguards.

Install only if you are comfortable giving an agent access to monetized creator accounts. Use a secure secret manager, avoid plaintext credential files, require manual review before posts or messages go out, and limit any automation to accounts and platforms you explicitly approve.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The skill describes broad automation behavior ('Automate your Buy Me a Coffee page') without clear trigger boundaries, approval requirements, or limits on when actions should execute. In a skill that can post content, message supporters, and promote links, ambiguous activation increases the risk of unintended account actions, spammy behavior, or misuse of connected accounts.

Missing User Warnings

High
Confidence
95% confidence
Finding
The skill instructs users to store login credentials for browser automation but does not include any warning about the sensitivity of those secrets, the risks of local storage, or safer handling practices. Because the workflow relies on direct account credentials for services without a public API, compromise of those values could lead to full account takeover, unauthorized posting, access to supporter information, and abuse of monetized accounts.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.