Repository Discovery

Security checks across malware telemetry and agentic risk

Overview

This repository-discovery skill is useful, but it asks agents to inspect real environment/config files and document API-key information without redaction guidance.

Install only if you are comfortable with broad repository inspection. Before using it, instruct the agent not to read real `.env` files or copy secret values, and require confirmation before creating or overwriting `REPO_DISCOVERY.md`.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill instructs the agent to produce a repository file (REPO_DISCOVERY.md) without requiring explicit user confirmation. In environments where the agent can write to the working tree automatically, this can create unintended file modifications, pollute commits, or alter repositories the user only wanted analyzed.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal