Back to skill

Security audit

Phy Git Branch Janitor

Security checks across malware telemetry and agentic risk

Overview

This is a user-directed Git branch cleanup guide with disclosed deletion commands, not an auto-running tool or hidden installer.

Before installing or using it, treat any generated delete command as a manual change plan. Review branch names carefully, confirm the default and protected branches, and be especially cautious with remote deletes because they remove branches from the shared remote for collaborators.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill generates copy-paste local and remote branch deletion commands, including `git push origin --delete ...`, without a strong, prominent upfront warning that remote deletions are destructive and can remove teammates' branches or disrupt active workflows. Although the skill includes some safeguards and review notes, the output format encourages bulk execution, which increases the risk of accidental destructive actions if classification is wrong or the repository is collaborative.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.