gh-modify-pr

Security checks across malware telemetry and agentic risk

Overview

This instruction-only skill uses GitHub and git to update a PR locally, and its file changes and commit behavior are disclosed and aligned with that purpose.

Install this only if you want an agent to use your configured GitHub access to read PR comments, clone or check out the repository, edit files, and create a local commit. Review the diff and commit before approving any push, and be cautious about running validation commands in unfamiliar repositories.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill description says it will 'modify code' but does not clearly warn that it may also clone a repository, change local files, and create a git commit as part of normal execution. That lack of upfront disclosure can lead users or calling agents to invoke the skill without understanding that it performs persistent local state changes, increasing the risk of unintended code modifications and commits.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal