Gcore FastEdge

Security checks across malware telemetry and agentic risk

Overview

This is a coherent Gcore FastEdge build-and-deploy helper, with expected but sensitive API-key and remote deployment behavior.

Install this only if you intend to work with Gcore FastEdge. Use a scoped or temporary GCORE_API_KEY where possible, avoid exposing it in shared shells or logs, and review the Wasm artifact and target app before running upload, create, or update commands.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The README says the skill will automatically activate for broad topics like 'edge computing' or 'Wasm deployment,' which are common and ambiguous terms. Overly broad auto-invocation can cause the wrong skill to engage in unrelated contexts, increasing the chance of unsafe actions, user confusion, or unintended deployment-oriented guidance being applied where it does not belong.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The deployment instructions tell users to export an API key and upload a binary to Gcore, but do not provide a clear warning that code artifacts and credentials are being sent to a third-party service. This is risky because users may execute the workflow without understanding the trust boundary, potentially exposing proprietary code or mishandling production credentials.

VirusTotal

67/67 vendors flagged this skill as clean.

View on VirusTotal