Content Analytics

Security checks across malware telemetry and agentic risk

Overview

This is a coherent content analytics skill, but users should treat the optional platform cookies as sensitive account credentials.

Install only if you are comfortable letting the agent use creator-platform session cookies to access analytics. Prefer official APIs or scoped tokens when available, avoid providing unnecessary cookies, and rotate or remove session cookies after use if exposure would concern you.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger phrases are very generic and could cause the skill to activate on broad content-analysis requests without clear user intent or scope. In a skill that may access creator dashboards and cookies, ambiguous activation increases the chance of unintended data access or scraping actions against connected accounts.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly requests platform cookies and mentions Playwright-based scraping, but does not warn users about privacy exposure, credential sensitivity, ToS/account-ban risk, or safe handling of session tokens. Cookies can grant direct account access, so collecting or pasting them into a skill without strong safeguards materially raises the risk of account compromise and unauthorized access.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal