Back to skill

Security audit

cli-hub

Security checks across malware telemetry and agentic risk

Overview

This is a broad CLI installation hub whose purpose is clear, but it includes tools with access to browser sessions, secrets, accounts, and publishing systems without enough safety scoping or consent guidance.

Review each listed CLI before installing it, especially tools that use browser sessions, password managers, account APIs, publishing platforms, infrastructure/admin systems, or persistent memory. Prefer isolated browser profiles and least-privilege accounts, and avoid matrix installs unless you have reviewed every included tool.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill functions as a package-discovery and installation hub for a large set of CLIs that can perform network access, browser automation, API calls, local file manipulation, and system-affecting actions, yet it presents installation and launch flows without any general safety notice or consent guidance. That omission increases the chance that a user or agent will install and invoke high-privilege or remote-connected tools without understanding trust boundaries, external execution, or downstream side effects.

Missing User Warnings

High
Confidence
97% confidence
Finding
The Browser CDP entry explicitly says it connects to an existing Chrome instance and inherits all cookies and sessions, which can expose authenticated state, private browsing data, and account actions to whatever agent or tool is using it. Advertising this capability without an explicit privacy and consent warning is dangerous because it normalizes access to live logged-in sessions and could enable account takeover-like actions, sensitive data extraction, or unintended transactions.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.