Back to skill

Security audit

NEXUS Commit Message

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed remote commit-message service, but it can transmit repository diffs to a paid third-party API and its automatic invocation and payment boundaries are not clearly scoped.

Install only if you trust NEXUS to process your repository diffs and payment proof data. Use sandbox mode first, redact secrets and proprietary content before submitting diffs, and require manual approval for any network call, wallet action, payment proof, or reusable payment mandate.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The README states the skill is "automatically invoked" when a matching task is detected, but provides no trigger boundaries, consent requirements, or examples of when invocation occurs. In an agent ecosystem, ambiguous auto-invocation can cause the skill to activate on unintended tasks and send repository diffs or other user content to a remote paid service without the user's clear awareness.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The README instructs users to POST input to a third-party remote endpoint but does not warn that commit diffs may contain sensitive source code, secrets, internal file paths, or proprietary information. In the context of a commit-message generator, the natural input is often a git diff, so the omission materially increases the risk of unintentional data exfiltration.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.