Back to skill

Security audit

Social Scheduler Pro Free

Security checks across malware telemetry and agentic risk

Overview

This is a social media planning skill with some unclear export and command-language, but no hidden scripts, credential use, posting automation, or destructive behavior was found.

Install only if you want a text-based social media planning assistant. Treat generated calendars and drafts as copy-paste content unless you explicitly ask the agent to create files, and review any proposed command or filesystem action first because the skill declares exec despite being mostly Markdown guidance.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
88% confidence
Finding
The skill documentation states the free version excludes automatic calendar export, yet earlier sections advertise create/query/export and export/save/convert operations. This inconsistency can mislead an agent into attempting export-related actions or presenting unsupported capabilities, which is dangerous when the skill has exec access and no clear boundary on what export/save means.

Intent-Code Divergence

Medium
Confidence
91% confidence
Finding
The document repeatedly contradicts itself about whether export is supported in the free version, creating ambiguous operational guidance for an agent. Ambiguity in capability definitions is a security issue because agents may overreach into file creation or transformation behaviors that users did not intend, especially in an exec-enabled skill.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The activation scope uses very broad natural-language keywords such as marketing copy, writing, title optimization, and content creation, which can cause the skill to trigger on common unrelated requests. Overbroad matching increases the chance of accidental invocation and unintended tool use, particularly because the skill declares exec capability.

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The skill describes export/save operations and is permitted to use exec, but it does not warn users about possible filesystem or system side effects. In an agent environment, undocumented write or command behavior can lead to unexpected file creation, overwriting, or command execution beyond the user's mental model.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.