blog-push

Security checks across malware telemetry and agentic risk

Overview

This is a local Hugo blog publishing helper that modifies selected blog files as documented, with no evidence of hidden network access, credential use, or unrelated behavior.

Install only if you want an agent-assisted Hugo publishing workflow. Before running it, confirm the Hugo directory and template paths point to the intended repository, and use git or backups because same-named article files may be overwritten and existing Markdown front matter will be replaced.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger phrases include broad natural-language requests such as '发布文章' and '创建博客', which can plausibly match normal conversation outside the intended workflow. In an agent environment, overbroad activation can cause unintended file operations, publication actions, or content movement when the user did not explicitly intend to run this skill.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill does acknowledge overwrite behavior and front matter removal, but only deep in the document and without prominent warnings or mandatory confirmation. Because the skill performs destructive content transformations, insufficient warning materially increases the risk of silent data loss, metadata destruction, and accidental replacement of existing published content.

VirusTotal

67/67 vendors flagged this skill as clean.

View on VirusTotal