Back to skill

Security audit

GitHub项目分析助手

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a project or repository analysis helper, with no artifact-backed evidence of hidden, destructive, or credential-stealing behavior.

Install only if you want the agent to help analyze repositories or projects. For private or sensitive code, explicitly limit what may be inspected or shared, and ask the agent to confirm before using web access or analyzing a repo when your request is vague.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger examples are broad conversational phrases like '帮我看看这个项目' and '分析一下 repo', which can overlap with normal discussion and cause the skill to activate when the user did not explicitly request this specific workflow. In an agent setting, unintended invocation can lead to unnecessary web access, expanded data collection, and response shaping that the user did not mean to authorize.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal