Indie Hacker

Security checks across malware telemetry and agentic risk

Overview

This founder-assistant skill is not malicious, but it tells the agent to take action, run scripts, and continue monitoring without clear user approval boundaries.

Install only if you want a highly action-oriented founder assistant. Before giving it tool access, set explicit rules requiring confirmation before scripts, code changes, CI/CD setup, deployments, account configuration, customer DMs, payments, or public posts. Keep ~/indie-hacker/ private and avoid storing secrets there.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs the agent to execute actions, configure tools, write code, and run scripts, but it provides no requirement for user confirmation, safety checks, or disclosure that files and environment state may be modified. In an agent setting, this creates a real risk of unauthorized or unexpected changes to local projects, credentials, CI/CD configuration, or other resources, especially because the skill frames action-taking as the default success condition.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal