my integration

Security checks across malware telemetry and agentic risk

Overview

This is a GitHub repository-analysis skill whose token and API use fit its stated purpose, with a privacy disclosure gap users should notice.

Before installing, treat this as a lightweight GitHub API helper rather than a complete audited implementation. Use a least-privilege GitHub token, assume repository names, branches, queries, and fetched repository content may be sent to GitHub, and avoid private or sensitive repositories unless you are comfortable with that data flow.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill explicitly uses a GitHub token and GitHub API access, but the documentation does not clearly disclose that user queries, repository identifiers, and potentially repository-derived content will be transmitted to an external service. This can mislead users about data flow and privacy boundaries, especially in agent environments where network access may be unexpected or sensitive.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal