Security audit
OSS Growth Attribution
Security checks across malware telemetry and agentic risk
Overview
This skill is a purpose-aligned research workflow for reconstructing open-source project growth from public GitHub and web evidence.
Before installing, expect the agent to browse public web sources and use GitHub API calls to analyze public repository growth. If providing a GitHub token, use the least-privileged token suitable for public read-only API access.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
64/64 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
