TopYappers - Creators & Viral Content Skills

Security checks across static analysis, malware telemetry, and agentic risk

Overview

This is a coherent TopYappers MCP integration that discloses its external API, API-key setup, and credit costs, with no artifact evidence of hidden code, exfiltration, or destructive behavior.

This skill appears safe to install if you intend to use TopYappers. Before installing, make sure you trust the TopYappers MCP endpoint, understand that an API key will be configured, and set expectations for when the agent may spend credits or retrieve creator contact/profile data.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Risk analysis

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

#
ASI03: Identity and Privilege Abuse
Low
What this means

If installed, the agent can use the configured TopYappers account credentials for searches and paid API calls.

Why it was flagged

The skill requires a TopYappers API key to authorize the MCP connection, giving the agent access to the user's TopYappers account and credits.

Skill content
**Auth:** Bearer token in the `Authorization` header

Get an API key at [topyappers.com/profile](https://www.topyappers.com/profile).
Recommendation

Use a dedicated or limited TopYappers API key if available, monitor credit usage, and remove the MCP configuration when no longer needed.

#
ASI07: Insecure Inter-Agent Communication
Low
What this means

Queries about creators, campaigns, competitors, or trends may be sent to TopYappers as part of normal tool use.

Why it was flagged

The skill connects the agent to an external MCP provider, so user prompts, search terms, and API credentials are used with that remote service.

Skill content
**MCP Endpoint:** `https://mcp.topyappers.com`
**Transport:** HTTP
Recommendation

Avoid sending confidential strategy, personal data, or sensitive business information unless you are comfortable sharing it with TopYappers under its terms.

#
ASI02: Tool Misuse and Exploitation
Low
What this means

The agent may spend TopYappers credits when using paid tools and may retrieve creator emails or demographic profile fields.

Why it was flagged

Several documented MCP tools consume account credits and can return creator contact/profile data; this is disclosed and aligned with the skill purpose, but users should be aware of cost and data-use implications.

Skill content
`get_creator_profiles` | Full profiles — followers, engagement, email, bio, niches | 1 credit/creator
Recommendation

Set clear instructions for when the agent may use paid tools, limit result counts, and review outputs before using creator contact data.