opencli-usage

Security checks across malware telemetry and agentic risk

Overview

This is a legitimate OpenCLI guide, but it gives an agent broad access to logged-in browser sessions, external CLI passthrough, plugin installs, and cached browser/network state without enough user-control boundaries.

Install only if you trust OpenCLI and are comfortable with an agent using logged-in browser/app sessions. Use a separate low-privilege browser profile, start with read-only discovery commands, manually approve any plugin, package, external CLI, or state-changing action, and clear or isolate the OpenCLI cache after sensitive work.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
This skill documents `opencli plugin install github:user/repo` and `opencli install <name>` auto-install flows that can fetch and execute third-party code, but it does so without an explicit safety boundary, trust model, or confirmation requirement. In an agent setting, that omission can normalize executing unreviewed code from git or package managers, leading to arbitrary code execution, supply-chain compromise, or installation of malicious tooling.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal