Back to skill

Security audit

AdaptlyPost

Security checks across malware telemetry and agentic risk

Overview

This skill is a clearly disclosed social-posting integration that uses a dedicated API key and includes strong confirmation rules for public posting and media uploads.

Install only if you want an agent to manage real social accounts through AdaptlyPost. Use a dedicated revocable token, connect only the accounts the agent needs, review every content/account/timing/visibility summary before approval, and prefer drafts for sensitive or unattended workflows.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Low
Confidence
86% confidence
Finding
This API reference exposes write-capable endpoints that can publish or schedule user-supplied content to external social media accounts, but it does not prominently warn that these are side-effecting actions requiring explicit user confirmation. In an agent skill context, that omission increases the chance of unintended posting, cross-posting, or bulk posting to real accounts if the agent acts on ambiguous instructions or transformed content.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The YouTube config documents `privacyStatus` with a default of `public` but does not warn users that omitting the field may immediately publish content publicly. In a social-post scheduling skill, this can cause unintended disclosure of unreleased, confidential, or internal media if callers assume drafts/private behavior by default.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.