Newrelic Cli Skills

Security checks across malware telemetry and agentic risk

Overview

This is a coherent New Relic CLI skill that needs account credentials and can change monitoring configuration, but the access is disclosed and aligned with its observability purpose.

Install only if you intend to let an agent use New Relic data and configuration commands. Use a least-privilege New Relic user key for the intended account, verify the active CLI profile before write actions, and manually confirm policy or condition IDs before running deletion commands because removing an alert condition can reduce monitoring coverage.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill documents a destructive command to delete an alert condition without any warning, confirmation step, or guidance to verify the target ID first. In an operational monitoring context, this can lead to accidental removal of alerting coverage, causing missed incidents and delayed detection of production problems.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal