Back to skill

Security audit

Error Message Improver

Security checks across malware telemetry and agentic risk

Overview

This is a low-risk writing and workflow skill for improving error messages, though its activation wording is broader than necessary.

This skill appears safe to install for drafting and improving error messages. Be aware that it may activate for broad debugging or support requests where a more specific skill would fit better; prefer explicit invocation when you want this behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases are broad and generic enough that the skill could activate for loosely related requests about productivity, support, or debugging without clear user intent. In an agent system, ambiguous activation boundaries can cause the wrong skill to take over a conversation, leading to inappropriate handling, prompt injection exposure through unnecessary context consumption, or workflow confusion.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are broad enough to match common support and productivity requests, which can cause the skill to activate outside its intended scope. In an agent ecosystem, overbroad activation increases the chance of prompt hijacking, unintended workflow execution, or the model preferring this skill when a narrower and safer capability should handle the request.

Vague Triggers

High
Confidence
96% confidence
Finding
The manifest description uses expansive activation terms like work-productivity, debugging, user feedback, support, and implementation support, which can match a very large fraction of ordinary user requests. This creates skill over-selection risk, where the agent may invoke this skill in contexts unrelated to error-message improvement, potentially displacing more appropriate skills and causing unsafe or low-quality task routing.

Vague Triggers

High
Confidence
98% confidence
Finding
The trigger keyword list is extremely broad and contains generic operational terms such as debugging, support, troubleshooting, and user feedback without any gating conditions. In skill-based agent systems, such unconstrained triggers can cause frequent unintended activation, making this a meaningful routing vulnerability that can interfere with normal tool selection and expose users to irrelevant or misleading workflow instructions.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The example trigger phrases are vague and close to ordinary natural language, which weakens the boundary between explicit invocation and incidental mention. Because examples often shape downstream activation behavior, these phrases can broaden matching and increase accidental invocation in everyday conversations that only mention help, workflow, or support at a high level.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger keywords are very broad and map to common support and debugging language, which can cause the skill to activate in many unrelated conversations. Over-broad activation increases the chance that the agent applies this workflow when not intended, creating prompt-selection confusion and potentially displacing more appropriate skills or safety logic.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example trigger phrases use everyday language broad enough to match many normal requests, without clear conditions for when this skill should or should not run. This can lead to accidental invocation and misrouting, especially in agent systems that rely on loose semantic matching or keyword heuristics.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The default prompt uses very generic language ('help me' plus broad productivity and support concepts) that can overlap with ordinary user requests, increasing the chance of unintended or implicit invocation. Because implicit invocation is enabled, this can cause the skill to activate outside clearly user-intended contexts, potentially injecting its behavior into unrelated conversations or workflows.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger sentence is broad enough to match ordinary user phrasing about help, workflows, or error messages, which can cause the skill to activate when the user did not explicitly intend to invoke it. Overbroad activation increases the chance of prompt hijacking at the routing layer, misapplication of the skill to unrelated requests, and reduced user control over which capability is used.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The invocation guidance includes a generic request pattern that overlaps with normal conversation, making accidental or adversarial triggering easier. In an agentic system, ambiguous routing can expose user inputs to the wrong skill, producing unintended transformations or enabling an attacker to steer execution by embedding common phrases.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.