Back to skill

Security audit

GitHub订阅

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a GitHub Trending helper, but its instructions and permissions are much broader and less clear than that purpose requires.

Review this skill carefully before installing. It is not evidence of theft or destruction, but it asks for broad agent tools and describes capabilities beyond a simple GitHub Trending feed. Use it only in a low-sensitivity workspace unless the publisher narrows the activation text, removes unsupported private-repo and Git-operation claims, and documents exactly what commands, files, tokens, and caches are used.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Intent-Code Divergence

Medium
Confidence
77% confidence
Finding
Claiming support for private repositories materially overstates the skill's access model and can cause users or agents to assume the tool is safe and authorized for private-repo handling. In a skill that includes exec/write capabilities, that mismatch can prompt operators to provide credentials or run the skill in more sensitive contexts than intended.

Vague Triggers

High
Confidence
89% confidence
Finding
The activation text uses very broad triggers like efficiency improvement, workflow automation, and batch processing, which are far wider than a simple GitHub Trending fetcher. In an agent environment with read/exec/write tools, overbroad activation can cause the skill to be invoked in unrelated contexts, increasing the chance of unnecessary command execution, data handling, or user confusion about the skill's authority.

Vague Triggers

Medium
Confidence
76% confidence
Finding
Ambiguous and truncated scenario descriptions make the skill's trigger boundaries unclear, which is risky in a tool-using agent system. Poor scope definition can lead the orchestrator or user to apply the skill to unrelated tasks, especially because the skill advertises exec capability and generic 'processing' behavior.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.