Back to skill

Security audit

Confluence CLI (confcli)

Security checks across malware telemetry and agentic risk

Overview

This Confluence skill is mostly coherent, but its install instructions ask an agent to run a mutable remote shell script for a tool that can modify or delete workspace content.

Review before installing. Prefer a pinned release or package-manager install with checksum or signature verification instead of running the raw `main` installer through a shell. Use a Confluence token with only the spaces and permissions needed, and require explicit confirmation before any create, update, delete, purge, attachment, comment, label, or copy-tree operation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.