README Auto Generator

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward README generator that reads a project and may update README.md, with no hidden code or persistence.

Before using it, review the generated README diff before committing or publishing, especially in private projects. Avoid letting generated documentation expose secrets, internal endpoints, proprietary implementation details, or sensitive configuration values.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly supports regenerating and updating an existing README, but it does not warn users that README.md may be overwritten or substantially rewritten. This can cause unintended loss of documentation content, especially because the skill presents the operation as automatic and comprehensive, increasing the chance of destructive edits without informed consent.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal