Dependency Upgrade

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward dependency-upgrade guidance skill with no hidden execution, credential access, or persistence beyond user-directed project changes.

Install this if you want an agent to help plan or perform frontend dependency upgrades. Review proposed package and lockfile changes carefully, especially for major version migrations or CVE-driven updates, and run the suggested verification commands before accepting changes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The description contains very broad activation phrases such as dependency upgrade, lockfile, CVE remediation, and version migration across multiple platforms, which can cause the skill to be selected for a wide range of common frontend tasks without clear scoping boundaries. In a review-quality skill, overbroad routing is risky because it may steer unrelated requests into a specialized workflow and influence package, lockfile, or migration decisions beyond the user's actual intent.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal