Back to skill

Security audit

version-updates

Security checks across malware telemetry and agentic risk

Overview

This skill performs a disclosed release-version update workflow, with some activation ambiguity users should watch for.

Install this if you want an agent-assisted release/version bump workflow. Before using it, confirm the target version, review the dry-run and git diff, and be aware that broad trigger words may invoke it when you only meant to ask about a version or release generally.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger list includes broad, common terms like 'version', 'release', and 'bump', which can cause the skill to activate in situations where the user did not intend to invoke a version-management workflow. In an agent setting, unintended invocation can lead to unnecessary file scans, edits, or follow-on actions across a repository.

Shadow Command Trigger

Medium
Category
Trigger Abuse
Confidence
86% confidence
Finding
Using 'version' as a trigger can shadow or conflict with a built-in command of the same name, causing the skill to intercept requests intended for core functionality. In an agent environment, command/skill ambiguity increases the chance of unintended execution and repository modification.

Shadow Command Trigger

Medium
Category
Trigger Abuse
Confidence
82% confidence
Finding
Using 'release' as a trigger can likewise conflict with a built-in command, creating ambiguity about whether the user intended a native release action or this skill's workflow. That ambiguity is risky because this skill is designed to inspect and modify multiple files and potentially run verification commands.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.