entr

Security checks across malware telemetry and agentic risk

Overview

This is a small, disclosed developer utility skill for using entr to run user-chosen commands when files change, with no hidden scripts or automatic behavior in the bundle.

Install only if you want an agent to use entr for development watch tasks. Review any command before running it, avoid shell-evaluated -s commands unless needed, and stop background watchers when they are no longer required.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Unrestricted Tool Access

Medium
Category
Excessive Agency
Content
---
name: entr
description: Run arbitrary commands when files change. Useful for watching files and triggering builds or tests.
---

# entr (Event Notify Test Runner)
Confidence
90% confidence
Finding
Run arbitrary commands

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal