Github Auto

Security checks across malware telemetry and agentic risk

Overview

This GitHub automation skill is not clearly malicious, but it needs review because it asks for GitHub token access while leaving some repository-changing behavior loosely scoped.

Install only if you are comfortable giving the agent GitHub access. Use a narrowly scoped token limited to the intended repositories, prefer read-only permissions unless write actions are needed, and require explicit confirmation before posting comments, labeling or closing issues, assigning reviewers, triggering CI, publishing releases, merging PRs, or deleting branches.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
83% confidence
Finding
The skill advertises broad, conversational triggers like helping inspect PRs and Issues without clearly defining activation boundaries, authorized repositories, or read-only vs write scopes. In an agent setting, vague invocation patterns can cause overbroad activation and unintended access to GitHub data or operations when the user did not explicitly request this skill.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal