Back to skill

Security audit

Github Manager Free

Security checks across malware telemetry and agentic risk

Overview

This GitHub helper is mostly purpose-aligned, but it gives an agent broad GitHub command authority while mixing read-only positioning with state-changing examples and broad triggers.

Review this skill before installing. It appears to be a GitHub CLI helper, not an exfiltration or destructive package, but use it only where you are comfortable letting an agent run gh commands against your repositories. Confirm any issue, PR, alias, or workflow-rerun action explicitly, and prefer narrowly scoped GitHub tokens for the repositories and actions you actually need.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The skill is presented as a free edition focused on read-only query/check tasks, but it documents state-changing operations such as rerunning workflows and setting persistent gh aliases. That mismatch can cause an agent or user to believe actions are low-risk when they can alter remote or local state, increasing the chance of unintended changes.

Intent-Code Divergence

Medium
Confidence
87% confidence
Finding
The stated free-version limitations contradict earlier examples that include write or automation-like behavior, which undermines user expectations and safe policy enforcement. In agent settings, inconsistent capability descriptions can lead to accidental execution of operations the user did not expect this edition to perform.

Vague Triggers

High
Confidence
84% confidence
Finding
The trigger condition is overly broad, effectively matching general coding, debugging, and deployment requests rather than narrowly scoped GitHub-management tasks. That increases the chance this skill is invoked in unrelated contexts where exec-enabled behavior may be unnecessary or unsafe.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The documentation includes a workflow rerun command that changes remote CI state, but provides no warning, approval step, or confirmation requirement. In an exec-capable agent, this can cause unauthorized or accidental reruns that consume CI resources and interfere with project operations.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill states that this capability supports create/query/export operations and the metadata grants write and exec tools, yet there is no unified warning about remote repository modifications. This combination makes accidental issue/PR/workflow changes more likely because users may assume the skill is primarily observational.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.