Back to skill

Security audit

GitHub + ACR 全周期发布管控

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed release-management skill that can perform powerful git, Docker, ACR, and SSH deployment steps, but its behavior matches its stated purpose and includes user-confirmation requirements.

Install only if you want an agent to help manage real release and deployment workflows. Use explicit commands, review every proposed git push/tag, Docker/ACR action, and SSH deployment before approval, and avoid using the generic triggers in casual repo discussions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger phrases include very broad terms such as “发布”, “push”, and “检查”, which can plausibly appear in normal conversation and may unintentionally invoke a workflow that performs release-related actions. In the context of a skill capable of tagging, pushing, building, and remote deployment, ambiguous activation materially increases the risk of accidental high-impact operations.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
This section describes safety-critical actions including git push, git tag, automated builds, remote server deployment, and post-deploy verification, but the nearby workflow description does not foreground strong warnings, dry-run behavior, or explicit approval checkpoints for each destructive or external action. Because the skill governs production release activity, insufficiently prominent safeguards can lead to unintended code release, infrastructure changes, or service disruption.

Vague Triggers

High
Confidence
96% confidence
Finding
The skill metadata advertises very broad trigger phrases such as “发布”, “检查”, “热更新”, and “下个版本”, which are common words in normal development conversations. In an agent environment, this can cause accidental invocation of a high-impact release/deployment workflow, increasing the chance of unintended git push, tagging, image publishing, or deployment actions after minimal conversational ambiguity.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger table repeats multiple ambiguous phrases including “检查”, “发布”, “push”, and “检查项目”, without defining contextual constraints or disambiguation rules. Because this skill orchestrates sensitive supply-chain and deployment operations, accidental matching could steer an agent into release-management behavior during ordinary repository discussion, making unintended external actions more likely.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.