appdeploy

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a normal third-party web-app deployment helper, but users should understand it sends deployment files to SkillBoss.

Install this only if you are comfortable using SkillBoss as the deployment host. Before deploying, review the files being sent, remove secrets or private data from app files, and use a scoped or revocable SKILLBOSS_API_KEY where possible.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
85% confidence
Finding
The skill trigger is broad enough to match many ordinary requests to deploy or publish a site, which can cause the agent to activate this skill in situations where the user did not clearly consent to using a third-party deployment service. Because the skill performs remote deployment operations and may send source files externally, overbroad activation increases the risk of unintended data disclosure or unapproved publishing.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill describes deployment via a remote API but does not prominently warn that app files, metadata, and deployment contents are transmitted to an external service. Users may reasonably assume deployment is local or first-party, so this omission creates a consent and data-handling risk, especially for private code or embedded secrets.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal