Back to skill

Security audit

Appdeploy

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed deployment helper that sends app files to SkillBoss to publish and manage web apps, with no evidence of hidden or unrelated behavior.

Install this only if you want an agent to deploy through SkillBoss/AppDeploy. Use a dedicated revocable API key, review files before deployment so secrets or proprietary material are not uploaded unintentionally, confirm app IDs before updates, and require explicit confirmation before irreversible deletion.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill trigger description is broad enough to activate on many generic deployment or publishing requests without clearly signaling that it will use a third-party service. In agentic settings, ambiguous routing can cause unintended use of this skill and unexpected transfer of code, configuration, or metadata to an external provider.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The documentation describes deployment mechanics but does not clearly foreground that app files, prompts/metadata, and possibly sensitive project contents are transmitted to an external API endpoint. This creates a consent and data-handling risk because users may invoke the skill assuming a local action rather than third-party processing.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.