Back to skill

Security audit

skill-github-project-analyzer

Security checks across malware telemetry and agentic risk

Overview

This is a prompt-only GitHub project analysis skill with disclosed public web lookup and report-writing behavior, with some usability and routing caveats but no evidence of hidden or harmful activity.

Install this if you want Chinese-language GitHub repository evaluation reports. Use clear GitHub URLs or owner/repo names to avoid wrong-project analysis, and be aware it may create a local Markdown report folder when used.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill uses broad, natural-language trigger phrasing like '快速分析一下这个项目', which can cause the agent to activate on vague user requests that may not clearly ask for this specific skill. Over-broad activation increases the chance of misrouting user intent, unnecessary external lookup behavior, and unintended processing of arbitrary URLs or project references.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The guidance says the skill can start from only a project name, e.g. '分析 React 项目', and then search for the official link automatically. This creates ambiguity and can lead to incorrect repository selection, unintended browsing, or activation from underspecified prompts where the user did not explicitly authorize external lookup.

Natural-Language Policy Violations

Medium
Confidence
83% confidence
Finding
The skill content is entirely written as a Chinese-only interaction pattern and does not offer language selection or fallback behavior. While not a direct code-execution risk, forced language behavior can degrade user control, cause miscommunication, and increase the likelihood of the agent ignoring the user's preferred language or misunderstanding security-relevant clarifications.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The skill description says it should be used when the user provides a GitHub link or asks to analyze a GitHub project, which is broad enough to match many ordinary requests. Overly permissive activation can cause unintended routing to this skill, leading the agent to fetch external content or produce file outputs when the user did not explicitly intend that workflow.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs the agent to generate a Markdown report and save it to a local directory without requiring explicit user notice or consent. Silent file writes can surprise users, create unwanted artifacts, and in some environments may overwrite files or persist sensitive analysis results to disk.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.