GitHub操作助手

Security checks across malware telemetry and agentic risk

Overview

This GitHub helper is purpose-aligned, but it gives agents examples for merging PRs and closing issues without clear confirmation or repository scoping guidance.

Install only if you are comfortable with an agent using your logged-in GitHub CLI context. Before allowing merges, issue closures, releases, or comments, require explicit repository, PR or issue number, and a confirmation step.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The activation phrases are broad enough to trigger on ordinary GitHub-related conversations, which can cause the skill to activate unexpectedly in contexts where the user did not intend repository-affecting actions. In a skill that includes PR merges, issue closure, and repo operations, overbroad activation increases the chance of accidental or unauthorized high-impact actions.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill exposes destructive operations like merging PRs and closing issues without warning, confirmation, or safety guidance. In an agent setting, this raises the risk of irreversible or workflow-disrupting actions being taken from ambiguous instructions or accidental invocation.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal