New Tag

Security checks across malware telemetry and agentic risk

Overview

This skill is a clearly disclosed release-tagging helper, but it can make real repository changes and trigger release automation if used.

Install this only if you want an agent to help perform real releases. Before allowing it to push, confirm the repository, branch, version, changed files, remote, tag name, and expected CI/CD or package-publishing effects.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill explicitly instructs the agent to commit, push a branch, create a tag, and push that tag to the remote, which can directly modify the repository and trigger downstream GitHub Actions or publishing workflows. Because it does not require an explicit confirmation step immediately before these irreversible remote actions, a user could invoke the skill in a way that causes unintended release publication or CI/CD side effects.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The default prompt authorizes a high-impact workflow—bumping versions, committing changes, and pushing a release tag—without defining narrow preconditions, confirmation requirements, or repository scope checks. Because tagging and pushing can trigger CI/CD, publishing, or downstream release automation, an overly broad invocation increases the risk of accidental or unauthorized release actions from ambiguous user requests.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal