AppDeploy

Security checks across malware telemetry and agentic risk

Overview

AppDeploy is a disclosed deployment helper that uploads app files to an external service and manages hosted apps, with sensitive but purpose-aligned capabilities users should handle carefully.

Use this only when you intend to deploy through AppDeploy. Review the files being uploaded, keep secrets out of app files, keep .appdeploy private and gitignored, and require explicit confirmation before deleting or overwriting an existing app.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
83% confidence
Finding
The trigger/description is broad enough that the skill may activate for generic requests to deploy or publish a site, even when the user has not clearly consented to sending code and app assets to a third-party service. In this skill’s context, unintended invocation is more dangerous because the workflow explicitly transmits files and metadata to a remote API and can create persistent public deployments.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill does not prominently warn that using it will send application files, metadata, and deployment details to an external HTTP API. That omission creates a meaningful data-handling and consent risk, especially for private source code, secrets accidentally included in files, or internal project metadata.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal