Back to skill

Security audit

FB 专业内容生成

Security checks across malware telemetry and agentic risk

Overview

This is a prompt-only marketing writing skill for FridayParts Facebook posts, with no evidence of hidden code, data access, credential use, or autonomous posting.

Safe to install for drafting FridayParts Facebook content. Review outputs before publishing, especially customer-review quotes and technical maintenance claims, and consider narrowing the triggers if accidental activation would be disruptive.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrase "facebook" is extremely broad and likely to match many ordinary user requests about Facebook, causing unintended activation of this skill. That can override user intent, inject branded posting behavior into unrelated conversations, and reduce reliability of the agent’s skill routing.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger "客评" is ambiguous and can refer to many contexts involving customer reviews, not specifically this Facebook-post generation workflow. This increases the chance of accidental activation and unintended content generation, especially in multilingual support or marketing conversations.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.