Back to skill

Security audit

社交情感分析免费版

Security checks across malware telemetry and agentic risk

Overview

This skill is a local CSV-based social sentiment analysis guide with proportionate Python and pandas use, though users should handle social-media data and API keys carefully.

Before installing, be aware that social-media exports can contain usernames, timestamps, message text, and other personal data. Use only data you are authorized to process, minimize or redact identifiers where possible, protect any platform API keys, and avoid sending sensitive CSV contents to external APIs or LLM services unless that is intended and permitted.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill discusses social-media data acquisition and API-based workflows but does not adequately warn users about privacy, network transmission, third-party API exposure, or handling of personal data in exported CSVs. In this context, users may process usernames, message content, timestamps, or other sensitive data and unknowingly send it across networks or into external services, creating avoidable privacy and compliance risk.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.