Back to skill

Security audit

dependency-graph

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward dependency-graph helper with disclosed codebase exploration and Mermaid rendering steps, with only a minor activation-scope caveat.

Install this if you want agents to analyze project imports and generate dependency diagrams. Be mindful that rendering through the Mermaid MCP may share dependency graph content such as module names and relationships with that tool, so avoid using it on sensitive repositories unless that is acceptable.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrases are broad enough to activate during common software-engineering conversations such as refactoring, coupling analysis, or circular dependency review. This can cause unintended skill invocation, increasing the chance that external agents or MCP tools are used when the user did not explicitly request them, which expands the attack surface and may expose repository context unnecessarily.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.