Instagram Agent - powered by Teneo Protocol
Security checks across malware telemetry and agentic risk
Overview
The skill appears to do what it claims (scrape public Instagram data via the Teneo network) but has some mismatches and risks you should understand before installing—most notably wallet/payment requirements and external network endpoints that are not declared in the registry metadata.
This skill seems to implement paid Instagram scraping via the Teneo network, which is plausible for its stated purpose — but proceed cautiously. Before installing or using it: (1) Review the @teneo-protocol/sdk package code on the linked GitHub and the npm package metadata to ensure it does not request private keys or transmit secrets to remote servers. (2) Confirm how wallet signing is performed (prefer local signing via a non-custodial wallet or hardware wallet; do NOT paste private keys into a webpage or SDK). (3) Test with a throwaway wallet and a very small USDC amount to confirm behavior. (4) Verify the backend WebSocket domain (backend.developer.chatroom.teneo-protocol.ai) is legitimate for the project. (5) Consider legal/ToS implications of scraping Instagram public data for your use case. If you want, provide the SDK repo/package URLs and I can check them for obvious red flags.
SkillSpector
SkillSpector findings are pending for this release.
VirusTotal
No VirusTotal findings
