Security audit
GitHub PAT Debugging
Security checks across malware telemetry and agentic risk
Overview
This skill is a focused GitHub token troubleshooting guide that uses the token only for GitHub diagnostics and warns against exposing the full secret.
Install only if you are comfortable using it while handling GitHub PATs. Follow its own safety rules: never print or paste the full token, rotate any token that was exposed, and review any Contents API write before running it.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
64/64 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
