Git Daily Report

Security checks across malware telemetry and agentic risk

Overview

This instruction-only skill is purpose-built to send scheduled Git change reports, with the external DingTalk delivery and recurring schedule disclosed.

Install only if the listed repositories are yours or authorized for monitoring, and verify that DingTalk target 1923216025-1426160278 is the intended recipient. Treat the scheduled job as ongoing sharing of commit details, changed files, statistics, and review findings until you remove it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The skill sets up an automated cron job that delivers repository commit data, file-change statistics, and code-review findings to a DingTalk target on an ongoing basis. Even if sent to the intended user, this creates a standing exfiltration path for potentially sensitive internal code metadata without an explicit warning, consent language, or data-minimization controls.

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal