Back to skill

Security audit

Postqued API

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Postqued integration skill that can publish or manage social content, but its high-impact actions are scoped and require confirmation.

Install only if you intend to let an agent operate Postqued with your organization API key. Treat publishing, scheduling, moderation, disconnects, collaborator changes, approvals, and deletes as real external actions; review the workspace, accounts, captions, destinations, and times before approving them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill description is extremely broad and action-oriented ('Trigger whenever an agent needs to read or change Postqued data... integrate Postqued into an automated workflow'), which can cause over-invocation for loosely related tasks. Because this skill enables externally visible writes such as publishing, scheduling, approvals, and account/workspace operations, accidental triggering could lead to unintended API calls against real organizational data.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The direct publishing workflow moves from a safe validation example to live execution with `dryRun: false` and an idempotency key, but it does not explicitly warn that this will immediately schedule or publish to real social accounts. In an agent skill context focused on automation, that omission raises the chance of unintended real-world actions, especially if an agent or integrator copies the example mechanically.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.