github-repo-search

Security checks across malware telemetry and agentic risk

Overview

This GitHub integration skill requests token-backed GitHub access for expected GitHub tasks, so it is not malicious but should be used with a limited token and care around write actions.

Install only if you intend to let an agent use GitHub through MCP. Prefer a fine-scoped GitHub token, avoid broad organization-wide permissions, and require explicit confirmation before creating branches, opening or editing PRs/issues, changing repository settings, or triggering CI workflows.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger phrases are broad and overlap with ordinary conversational requests such as asking to 'search GitHub' or 'see what's on GitHub'. In an agent/router environment, this can cause unintended invocation of the skill, leading to actions or responses the user did not explicitly intend and increasing the attack surface for prompt-routing abuse.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal