Supapost

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Supapost social-content integration, but users should carefully approve any action involving connected social accounts.

Install this only if you want your agent to work with Supapost and connected social accounts. Before approving scheduling, publishing, deleting, or account-specific changes, verify the platform, account, media, caption/title, timing, and reversibility.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The skill description uses very broad trigger language ('use whenever the user asks to create social content') that can cause the agent to invoke this external MCP for loosely related requests. This increases the chance of over-activation, unnecessary access to connected social accounts, and unintended execution of write-capable operations in a context broader than the user likely expects.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal