Back to skill

Security audit

instagram-data

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Instagram API skill that sends user queries and an API key to superagnt for the expected purpose, with no local code execution or persistence found.

Install this only if you are comfortable sending Instagram research targets and your superagnt API key to superagnt. Prefer storing the key in SUPERAGNT_API_KEY, avoid pasting secrets into prompts or logs, and use the download-link endpoint only when you have the right to retrieve that media.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill description emphasizes Instagram intelligence features but does not clearly warn that usernames, URLs, hashtags, location identifiers, and similar inputs are sent to a third-party service operated by superagnt. In an agent setting, this can cause users to unknowingly transmit sensitive research targets or operational interests to an external processor.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

This step sends the user's bearer token to api.superagnt.com to verify credits and connectivity, which is an external transmission of credentials and account metadata. While expected for an API client, it remains security-relevant because it relies on trust in a third-party service and may expose usage/account information outside the local environment.

Content

Scanner excerpt · SKILL.md (reported line 64)May include surrounding context.

One call proves the key, the credit balance, and this source end to end:

bash
curl -s https://api.superagnt.com/v1/credits \
  -H 'Authorization: Bearer $SUPERAGNT_API_KEY'

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The base URL establishes that all Instagram queries and identifiers handled by this skill are transmitted to api.superagnt.com. In context, this is core functionality rather than hidden exfiltration, but it is still a genuine external data transfer risk because user inputs and possibly sensitive targeting data leave the local system.

Content

Scanner excerpt · SKILL.md (reported line 74)May include surrounding context.

Base URL

text
https://api.superagnt.com/v1/data/instagram

Available Endpoints

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill is presented as Instagram research/data access, but it also exposes a /post-dl endpoint that can be used to obtain downloadable media links. That materially expands the capability from analytics/research into content retrieval, which can surprise users and increase legal, policy, and abuse risk if an agent uses it without explicit user awareness or consent.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The example demonstrates making a live request to the external API and includes a placeholder for directly embedding an API key in a header. Even as sample code, this pattern can encourage insecure handling of secrets and confirms external transmission of credentials and request metadata to a third party.

Content

Scanner excerpt · SKILL.md (reported line 677)May include surrounding context.

Example

bash
curl -X GET 'https://api.superagnt.com/v1/data/instagram' \
  -H 'X-API-Key: your_api_key_here' \
  -H 'Content-Type: application/json'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 696)May include surrounding context.

md
nothing else. The same API key also works with superagnt's other data sources
and platform tools, but those are separate listings that the user installs or
enables themselves; this skill does not add or enable anything beyond what is
documented here. The public catalog is at `https://api.superagnt.com/v1/platforms`.

## Links

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The document states authentication uses Authorization: Bearer $SUPERAGNT_API_KEY, but the later example uses X-API-Key: your_api_key_here. Inconsistent auth instructions can cause failed requests, unsafe troubleshooting, or accidental credential mishandling when users or agents try multiple header formats and expose secrets in logs or prompts.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.