tech-trending-on-github

Security checks across malware telemetry and agentic risk

Overview

This appears to be a low-risk GitHub Trending helper with a minor activation-scope issue, not evidence of harmful behavior.

Install if you want GitHub Trending assistance. Be aware it may activate on vague requests about what is popular today, so clarify whether you mean GitHub/open-source trends when asking broad popularity questions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrases are broad enough to match generic requests like '今天有什么热门' or 'what is popular today', which can cause the skill to activate outside clearly GitHub-specific intent. This is a scope/quality issue rather than direct code execution, but it can hijack unrelated conversations and force unnecessary web fetches to GitHub Trending, reducing reliability and potentially exposing users to unintended external-content processing.

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal