instagram-place-posts
What this skill does
The skill is designed to scrape Instagram posts tagged at a specific location or place. It uses browser automation to interact with Instagram's API and retrieve media items, captions, like/comment cou
github/browser-act - Data Exfiltration - 5.3k stars
Threat analysis
Skill info
pkg:github/browser-act/skills@4577dc5?skill=instagram-place-postsAssessments (2)
Data Exfiltration
Data Exfiltration via local-llm-review
scripts/get-place-posts.py
The script sends a POST request to 'https://www.instagram.com/api/v1/locations/{args.location_id}/sections/' with the 'max_id', 'tab', and 'session_id' parameters. While the target is a legitimate InsCSRF Token Handling
CSRF Token Handling via local-llm-review
scripts/get-place-posts.py
The script extracts the CSRF token from the browser's cookies and includes it in the request headers. If the script is used in a context where the user is logged into Instagram, this could be exploiteBadge
Add the Anomity scan badge for instagram-place-posts to your README.
How Anomity governs this at runtime
Scan-time vetting tells you what a skill says it will do. Anomity's Endpoint Sensor sees what agents actually do: it discovers skills alongside every other AI artifact on the endpoint, and runtime governance can allow, deny, or log the tool calls a skill triggers. Policy violations route to your SIEM, Slack, email, or Jira, backed by a queryable 90-day audit trail.
Book a 30-minute demo to see your own skill inventory.
Methodology and disputes
Every skill is assessed by the Anomity Skill Intelligence engine against its public source; findings indicate risk patterns, not confirmed exploitation. Maintainer of instagram-place-posts? Report an issue or request a rescan.




