Back to skill

Security audit

Repo Growth Operator

Security checks across malware telemetry and agentic risk

Overview

This is a small repository-growth planning skill with no executable code, persistence, credential handling, or hidden install behavior.

Install this if you want lightweight growth-planning advice for public repositories. Prefer explicit prompts that name the repository and task, and avoid using it on private or sensitive repos unless you intend that context to be analyzed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill enables implicit invocation without any narrowing conditions, which allows the agent to select and run this skill based solely on broad relevance. That increases the chance of unintended activation in unrelated conversations, potentially exposing repository analysis or recommendation behavior where the user did not explicitly request it. In a security context, over-broad auto-invocation expands attack surface and can be abused through prompt steering or context injection.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.