fastgithub

Security checks across malware telemetry and agentic risk

Overview

This GitHub speed-up proxy is purpose-aligned but asks users to make broad system and network trust changes that need careful review.

Install only if you trust the publisher and can independently verify the FastGithub binary. Avoid installing the custom root CA or disabling Git SSL verification unless you understand the TLS interception risk, and remove any proxy environment settings, certificates, and background processes when you are done.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The documentation instructs users to persistently set http_proxy and https_proxy in ~/.bashrc, which changes network behavior for future shell sessions beyond the immediate FastGithub use case. This can unintentionally route unrelated traffic through a local proxy and make later security issues harder to detect or troubleshoot, especially if users forget the setting remains enabled.

Missing User Warnings

High
Confidence
96% confidence
Finding
The skill recommends installing a custom root CA certificate into the system trust store without a strong warning that this grants the local proxy authority to intercept and re-sign TLS connections. Trusting a new root CA is a sensitive security action that expands the system's trusted computing base and can enable man-in-the-middle interception if the proxy or certificate is compromised.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal