Back to skill

Security audit

conventional-git

Security checks across malware telemetry and agentic risk

Overview

This skill is a conventional Git workflow guide with disclosed git-related permissions and no evidence of hidden, destructive, or unrelated behavior.

Install this if you want consistent branch, worktree, and Conventional Commits guidance. Review any proposed git or gh command before execution, especially actions that create/remove worktrees, commit changes, push branches, or modify GitHub resources.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The description says to use the skill for broad situations like "writing commits," "reviewing branch conventions," and when a user asks how to create or organize worktrees. These conditions are expansive and do not clearly define when this skill should activate versus when a more general git or project workflow skill should not, increasing the chance of unintended invocation.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.