Back to skill

Security audit

g1geo

Security checks across malware telemetry and agentic risk

Overview

The skill is coherent with a G1GEO CLI integration, but it tells agents to install or update a global CLI package automatically and then use account-level business and publishing authority.

Install only if you trust G1GEO and are comfortable with an agent installing or updating a global npm CLI and using authenticated account-level access for content, product, reporting, and publishing workflows. Review CLI install behavior and publishing permissions before use, especially in shared or production environments.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

High
Confidence
96% confidence
Finding
The skill’s trigger scope is extremely broad, covering generic knowledge, writing, diagnostics, publishing, and content tasks. That increases the chance the skill will activate in unrelated contexts and then steer the agent into privileged CLI usage, authentication, or operational workflows the user did not specifically request.

Missing User Warnings

Medium
Confidence
98% confidence
Finding
The skill directs the agent to install or update software immediately and explicitly says not to ask for separate confirmation solely because the CLI is missing. This can cause unauthorized system modification, unexpected package installation, and supply-chain exposure, especially because it uses a global install of the latest version rather than a pinned, preapproved release.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.