Skylv Git Helper

Security checks across malware telemetry and agentic risk

Overview

This is a simple instruction-only Git helper with no executable code, credentials, persistence, or hidden behavior.

Review any Git command before running it, especially reset, checkout, merge, or branch operations, because normal Git advice can still change repository state. The version mismatch between registry metadata and SKILL.md is a minor provenance note, not a security concern by itself.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill metadata uses broad Git-related triggers and descriptive terms that are likely to activate during ordinary conversation about commits, branches, merges, or pull requests. In an agent environment, over-broad activation can cause unintended skill invocation, letting this skill intercept requests outside the user's explicit intent and potentially influence repository operations or advice inappropriately.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal