博客发布规则 本项目是 astro-koharu 博客。博客发布规则

Security checks across malware telemetry and agentic risk

Overview

This is a scoped blog-publishing helper that can create posts and run the site build for one named Astro blog, with the main risk being accidental use on the wrong server or request.

Install this only on the server that hosts the intended Astro Koharu blog. Before using it, confirm the target path and pnpm build script are trusted, and treat publish requests as real site changes because the skill can create posts and rebuild the public static site.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill description includes broad trigger phrases such as generic requests to publish, generate, classify, and tag blog posts, which can cause the agent to invoke this skill in contexts that are only loosely related. Because the skill performs filesystem writes and runs a build command on a live server path, accidental invocation could lead to unintended content creation or modification in a production-adjacent environment.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal