Back to skill

Security audit

NEXUS Changelog

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed paid remote changelog service, but automatic invocation with payment credentials and repository text creates review-worthy spending and privacy risk.

Install only if you trust NEXUS with the changelog text you submit and with the payment proof used for requests. Use sandbox or low-value credentials first, avoid sending secrets or private unreleased repository data, and configure your agent to ask before paid calls.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The README states the skill is 'automatically invoked' when a matching task is detected, but it does not define trigger boundaries, approval requirements, or what data may be sent during invocation. In an agent ecosystem, ambiguous auto-invocation can cause the skill to activate unexpectedly and forward task content to a remote paid service, increasing the risk of unintended data disclosure and unauthorized actions.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The README provides direct API usage that posts user-supplied input to an external host, but it does not clearly warn that prompts, commit history, or changelog source material will leave the local environment. For a changelog skill, those inputs may include proprietary code history, internal issue descriptions, or unreleased product details, so omission of a transmission warning materially increases privacy and confidentiality risk.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.