Back to skill

Security audit

Error Message Improver

Security checks across malware telemetry and agentic risk

Overview

This skill is a documentation-only helper for improving error-message wording, with no executable code or hidden data access found.

This appears safe to install as a lightweight writing and workflow helper. Users should be aware that its trigger wording is broad, so they may want to invoke it explicitly for error-message work or tighten implicit routing if their environment supports that.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger sentences are generic enough to match ordinary support, debugging, and productivity requests, which can cause this skill to activate outside its intended scope. Over-broad invocation increases prompt-surface area and can unintentionally intercept unrelated user tasks, making downstream instruction handling less predictable and easier to abuse through opportunistic routing.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrases are broad enough to match routine requests about productivity, support, or debugging, which can cause the skill to activate outside its intended scope. In an agent environment, overscoped activation can steer unrelated conversations into this workflow, increasing the chance of misrouting, prompt hijacking surface, or user confusion even if the README itself contains no executable payload.

Vague Triggers

High
Confidence
95% confidence
Finding
The skill description uses broad activation terms like work-productivity, debugging, user feedback, support, and implementation support, which overlap heavily with common user requests. This can cause the skill to activate outside its narrow purpose and steer unrelated conversations, increasing the chance of inappropriate delegation, prompt collisions, or misuse of the skill in contexts it was not designed to handle.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger keywords and example phrases are overly generic and match routine support or debugging language that appears in many unrelated requests. In a skill-routing system, this increases accidental invocation and can let the skill intercept broad classes of conversations, reducing routing precision and potentially overriding safer or more appropriate skills.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger keywords are broad and overlap with common support and debugging conversations, which can cause the skill to activate outside its intended scope. Over-broad activation increases the chance that the agent applies this workflow to unrelated requests, leading to prompt-routing confusion, unintended disclosure of user context into the skill flow, or degraded security controls that depend on precise skill selection.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The description states broad activation categories such as work-productivity, debugging, support, and user feedback without clearly bounding what requests are in or out of scope. Ambiguous activation criteria can cause the skill to be selected for many ordinary requests, creating misrouting risk and making it easier for adversarial or irrelevant inputs to steer the agent into an unintended workflow.

Vague Triggers

Low
Confidence
80% confidence
Finding
The example trigger phrases use highly generic help-request wording and do not provide counterexamples that would reduce accidental invocation. This makes false activation more likely in normal conversation, which can waste agent actions and apply specialized instructions where they are not appropriate.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The default prompt uses a very generic phrase ('Use $error-message-improver to help me ...') tied to broad everyday concepts like productivity, debugging, support, and user feedback. Because implicit invocation is enabled, this overlap can cause the skill to trigger in ordinary conversations where the user did not clearly intend to invoke it, creating prompt-scope confusion and increasing the chance of unintended agent behavior.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger sentence is so generic that it can match ordinary user requests unrelated to explicitly invoking this skill, causing unintended activation. In an agent system, overly broad routing increases the chance the wrong skill is selected, which can leak context, produce irrelevant actions, or override a more appropriate and safer workflow.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.