agentcli-go

Security checks across malware telemetry and agentic risk

Overview

This is a developer reference skill for a Go CLI framework; its command execution and file-writing topics are disclosed and fit the purpose, but users should keep it scoped to CLI development work.

Install this if you are actively working with agentcli-go or scaffolding Go CLI projects. Before using generated commands or templates, review what files will be written and what shell commands will run, and avoid letting the skill guide unrelated "add command" requests unless the repository is actually an agentcli-go project.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger list includes broad terms such as "add command" and "agentcli" that are likely to match many unrelated user requests, causing this skill to be invoked outside its intended scope. Over-broad activation can inject irrelevant framework-specific guidance into unrelated tasks, increasing the chance of incorrect actions, context contamination, or misuse of the skill as a prompt-injection vehicle.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal