Back to skill

Security audit

GitHub Repo Standardizer

Security checks across malware telemetry and agentic risk

Overview

This skill openly standardizes GitHub repositories and its write actions are disclosed with reasonable preflight and confirmation safeguards.

Before installing, be aware this skill can make persistent GitHub repository changes, including labels, workflow files, docs, and branch protection rules. Use it only with the intended repository, review the dry-run plan carefully, and do not grant org/admin token scopes unless you actually want org or ruleset changes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The invocation examples are broad enough that an agent could apply repository-wide changes based on casual user phrasing without strong scoping or confirmation requirements. In a skill that edits labels, CI, branch protections, and docs, ambiguous triggers increase the chance of unintended modifications to the wrong repository or of more modules running than the user intended.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The invocation phrases are broad enough to match routine requests like 'tidy up' or 'professionalize this repo', which can cause the skill to activate in situations where the user did not intend repository-wide administrative changes. Because this skill performs high-impact GitHub operations such as pushing workflow files, changing labels, and modifying rulesets, accidental invocation increases the risk of unintended repository modifications.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.