Back to skill

Security audit

Social Note Compliance Audit

Security checks across malware telemetry and agentic risk

Overview

This skill coherently sends user-provided social-note text to a disclosed external audit API and does not show hidden persistence, local data access, or destructive behavior.

Install only if you are comfortable sending the note text you audit to ai.wsdsocial.com using your WSD_API_KEY. Avoid submitting secrets, personal data, or confidential unpublished copy unless that third-party transfer is acceptable, and invoke it only for social-note compliance review.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger terms include broad, common words such as 'audit', 'compliance', and 'moderation', which can cause the skill to activate in contexts unrelated to Xiaohongshu note review. That increases the chance that users will unknowingly route arbitrary text to this external service, creating privacy and data-handling risk and causing inappropriate tool use.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs sending full note content to https://ai.wsdsocial.com but does not warn users that their text is transmitted to a third-party API. Users may submit unpublished marketing copy, personal data, or sensitive business content without informed consent, leading to confidentiality and privacy exposure.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.