Security audit
OpenRank
Security checks across malware telemetry and agentic risk
Overview
This skill only guides an agent to fetch public OpenDigger metrics for GitHub or Gitee projects and present them to the user.
Install only if outbound requests to oss.open-digger.cn are acceptable in your environment. Requests for all metrics may trigger many public JSON fetches, but the skill does not ask for credentials or local data access.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
65/65 vendors flagged this skill as clean.
