Back to skill

Security audit

Reddi Git Summary

Security checks across malware telemetry and agentic risk

Overview

This skill only asks the agent to run local, read-only Git summary commands, though the resulting summary can reveal private repository details.

Install this only if you are comfortable letting the agent summarize local Git repository metadata. Review generated output before sharing it, especially remote URLs, branch names, commit messages, contributor names, and changed file paths from private projects.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The usage guidance says to invoke the skill when the user asks for 'a git summary, repository overview, or wants to understand the current state of a git project.' Phrases like 'repository overview' or 'understand the current state' are broad and lack clear boundaries or exclusion conditions, which can cause unintended activation in general Git-help conversations.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.