Chief Feature Workflow

Security checks across malware telemetry and agentic risk

Overview

This skill appears to automate feature development in a way that can modify repositories, push changes, open pull requests, and approve command execution with too little user control.

Install only if you want an agent to drive repository-changing feature work. Use it in trusted repos, avoid always-allow command approvals, review commands before execution, and require explicit confirmation before commits, pushes, PR creation, or branch/worktree deletion.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are broad enough to activate on ordinary software-development requests, causing this skill to run in contexts where the user did not explicitly ask for Chief-driven automation. Because the skill performs branching, worktree creation, commits, pushes, and PR creation, over-broad activation increases the chance of unintended repository changes and autonomous execution.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The workflow instructs the agent to create branches and worktrees, copy files, commit changes, push to origin, open a PR, and later delete worktrees and branches, but it does not present a clear upfront warning that these actions modify the repository and may have remote side effects. In a skill context, omission of explicit consent and risk disclosure makes accidental destructive or externally visible actions much more likely.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal