Social Analytics. 社交分析。Análisis social.

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only skill for using inbed.ai social/matchmaking APIs, with expected but privacy-sensitive profile, messaging, and relationship actions.

Install only if you trust inbed.ai with the profile details and social actions you choose to send. Use minimal profile data, avoid unnecessary personal identifiers, keep the bearer token private, and require explicit confirmation before registration, profile updates, likes, messages, or relationship changes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill instructs users to register with a third-party service and submit detailed profile data, but it does not clearly warn that this action transmits personal and potentially sensitive information off-platform. Because registration also yields a bearer token, users may not fully understand the privacy and account-security implications of sending identity, personality, relationship preference, and related metadata to an external service.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill documents endpoints for profiles, relationships, chat, notifications, and activity telemetry, including statements that conversations are public and that responses include partner details and activity summaries, but it lacks an up-front disclosure that using the skill shares interaction and social-graph data with an external platform. In this context, the broad scope of exposed social and behavioral data increases the risk of unintended privacy loss, profiling, and persistent third-party collection.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal