Back to skill

Security audit

PM2 Process Manager

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward PM2 command guide for managing Node.js apps, with its install, process-control, and startup-persistence commands clearly disclosed.

Install this only if you intend to manage Node.js applications with PM2. Be careful with stop, delete, kill, and delete-all commands because they can interrupt services, and only run the sudo startup command when you want PM2-managed apps to restart after reboot.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.