Puter Deployer

Security checks across malware telemetry and agentic risk

Overview

This is a focused Puter deployment helper with disclosed CLI, shell, and URL verification steps, though users should confirm targets before any production update.

Install this only if you want an agent to use your Puter CLI login for deployments. Before running it, confirm the account, target app/site, build output directory, production overwrite intent, expected URL, and rollback artifact.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding
The skill advertises deployment, update, troubleshooting, and rollback capabilities, but the documented behavior only performs preflight checks and URL verification while deferring actual deployment to vague fallback guidance. This mismatch can mislead users or downstream agents into believing a production deployment or rollback occurred when it did not, causing unsafe operational decisions and potential service disruption.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal