Back to skill

Security audit

MEGAcmd for Developer

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only developer guide for building and debugging MEGAcmd, with no hidden execution or mismatched behavior found.

Install this only if you want agent help with MEGAcmd development tasks. Review commands before running them, especially sudo installs, Docker builds, and any integration tests that use a MEGA account or real sync folders.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill states it is automatically activated for broad 'MEGAcmd development' context and can also be forced by common phrases. In agent frameworks, ambiguous activation can cause the wrong skill to trigger in situations involving MEGAcmd generally, leading the agent to follow build/debug workflows or repo-specific guidance when the user intended unrelated operations, increasing the chance of unintended command suggestions or context confusion.

Vague Triggers

Medium
Confidence
86% confidence
Finding
A ativação automática baseada em palavras-chave amplas pode fazer a skill ser selecionada em contextos apenas parcialmente relacionados a desenvolvimento do MEGAcmd. Isso aumenta a chance de uso indevido da skill, aplicação de instruções inadequadas ao contexto do usuário e expansão desnecessária da superfície operacional do agente.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.