Back to skill

Security audit

GitHub

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed GitHub integration that uses Maton-managed OAuth and gives clear approval rules for write actions.

Before installing, understand that this can reach broad GitHub REST API functionality through Maton. Use OAuth, connect only the GitHub account and scopes needed for the task, confirm every write or destructive action, and revoke unused Maton/GitHub connections when finished.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The manifest describes the skill as scoped to a narrower set of GitHub objects, but the documented `maton api '/github/{native-api-path}'` passthrough effectively exposes arbitrary GitHub REST endpoints. That mismatch can mislead an agent or user into granting or using broader capabilities than the manifest suggests, including org-level and other unmanaged operations.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.