Bring Recipes

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a browse-only Bring recipe helper, with the main caution being that it asks for Bring login credentials via environment variables.

Before installing, inspect the actual CLI source and npm dependencies because only the instructions were submitted here. Use the Bring credentials only in a trusted local shell, avoid putting the password in shared profiles or CI logs, unset it when done, and rotate the password if it may have been exposed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The documentation instructs users to place their Bring! account password in a plaintext environment variable, but it does not warn about credential sensitivity or safer handling practices. Environment variables can be exposed through shell history, process inspection, crash logs, CI output, or inherited subprocess environments, so this guidance increases the chance of credential leakage.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal