ghst for Ghost

Security checks across malware telemetry and agentic risk

Overview

This skill gives an agent broad but clearly disclosed Ghost CMS administration access, with safeguards for high-risk actions and credential handling.

Install this only if you want an agent to administer a Ghost publication. Use a dedicated low-privilege staff token where possible, pin or intentionally review the @tryghost/ghst package version, keep credentials out of shared logs, and manually review publish, delete, bulk, import/export, webhook, settings, theme, social posting, or raw API actions before approving them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The documentation advertises commands that store credentials and print a short-lived staff JWT, but provides no warning about secure storage, terminal/log exposure, shell history, or least-privilege handling. In a skill that exposes full Ghost Admin API access, this omission can lead users or downstream agents to reveal or mishandle sensitive tokens, enabling unauthorized administrative actions if those credentials are captured.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal