Back to skill

Security audit

App Builder

Security checks across malware telemetry and agentic risk

Overview

This app deployment skill is legitimate, but it gives an agent broad deployment authority and tells it to upload local .env variables to Vercel without a required review step.

Install only if you intend to let an agent create repos, push to main, deploy to Vercel, and manage app environment variables. Before use, confirm the exact app folder and deployment target, and review each .env key before allowing anything to be uploaded to Vercel.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The skill description is broadly scoped to nearly any request involving creating, modifying, fixing, or deploying an app, which increases the chance the agent will invoke this high-privilege skill in situations where it is unnecessary or insufficiently scrutinized. Because the skill can use GitHub, Vercel, and Instant CLI and directs work in a real apps directory, overbroad activation expands the blast radius of mistaken or prompt-injected use.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill instructs the agent to push local .env variables to Vercel without requiring explicit user consent, secret review, or filtering, which can transmit sensitive credentials to a third-party platform. In context, this is more dangerous because the skill is specifically designed to deploy apps and operate with real CLI access, making accidental exfiltration or propagation of unrelated local secrets plausible.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.