Back to skill

Security audit

GitHub PAT Debugging

Security checks across malware telemetry and agentic risk

Overview

This skill is a focused GitHub token troubleshooting guide that uses the token only for GitHub diagnostics and warns against exposing the full secret.

Install only if you are comfortable using it while handling GitHub PATs. Follow its own safety rules: never print or paste the full token, rotate any token that was exposed, and review any Contents API write before running it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.