Cross Poster

Security checks across malware telemetry and agentic risk

Overview

This is a content-drafting skill for social media, with no evidence of hidden posting, credential access, persistence, or code execution.

Install this if you want help drafting public-facing social posts. Because some triggers are broad, avoid invoking it on confidential or unpublished material unless you intend to turn that material into social copy, and review all drafts before posting.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases include generic terms like "share this," "announce," and "cross-post," which can overlap with ordinary user requests and cause the skill to activate in contexts where social-post generation was not explicitly intended. Over-broad activation increases the chance of unintended data disclosure or inappropriate transformation of user content into public-facing copy, especially if the surrounding system auto-selects skills based on trigger text.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal