Back to skill

Security audit

Github Stars Playbook

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward marketing playbook for growing GitHub stars, with no hidden automation, credential access, or privileged behavior in the artifacts.

Before installing, consider that the skill may guide your agent to draft or plan public promotional posts and outreach. Use it with normal review of platform rules and your project's messaging, especially for Reddit, Hacker News, email, and community channels.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The entire skill description is presented only in Japanese, and there is no indication that users can select another language or that this locale restriction is required for a region-specific purpose. Per the policy, forcing a specific language without user opt-in is a natural-language policy concern.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.