Back to skill

Security audit

Error Message Improver

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only helper for improving error messages, with broad auto-invocation wording but no hidden code, credential access, persistence, or destructive behavior.

Use this skill if you want help rewriting or systematizing application error messages. Be aware that its broad trigger wording may activate during general debugging or support conversations, so prefer explicit invocation or tighter routing settings where available.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger sentence is broad enough to overlap with ordinary requests about help, workflows, or error messages, which can cause the skill to activate outside its intended scope. In an agent system, overly generic activation increases the chance of prompt-routing mistakes, unexpected instruction injection into unrelated conversations, or accidental use when a user did not explicitly request this skill.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The activation guidance is ambiguous because it does not clearly separate explicit invocation from illustrative examples, and the trigger sentences are phrased so generally that many unrelated user requests could match them. This weakens routing safety by making unintended activation more likely, especially in multi-skill environments where broad patterns can override more appropriate skills.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrases are generic enough to match ordinary support and productivity requests, which increases the chance of unintended skill invocation. In an agent ecosystem, over-broad activation can route user input into the wrong workflow, causing confusion, inappropriate handling of data, or accidental execution of skill-specific logic outside the user’s intent.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger keywords are broad and overlap with many ordinary support and debugging requests, which can cause the skill to activate when a more specific or appropriate skill should handle the task. That increases the chance of context misrouting, unnecessary prompt expansion, and inconsistent behavior, especially in environments with multiple overlapping skills.

Vague Triggers

High
Confidence
91% confidence
Finding
The description allows invocation for a very wide range of tasks including work-productivity, debugging, user feedback, support, and general implementation assistance, without defining clear boundaries. In a multi-skill agent, this can lead to over-invocation and routing capture, where this skill intercepts unrelated requests and influences outputs outside its intended scope.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger keywords include very broad, everyday terms such as 'debugging', 'support', and 'user feedback', which can overlap with many unrelated user requests. This can cause the skill to activate outside its intended scope, leading to prompt-routing mistakes, irrelevant behavior, or unintended influence over conversations that did not specifically request this workflow.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The example trigger phrases use broad help-seeking language like 'Help me' and 'I need a practical workflow' with only loosely scoped task text, which trains or encourages matching on generic requests rather than a narrowly defined capability. In practice, this increases accidental invocation risk and can make the skill capture unrelated requests that merely resemble ordinary assistance queries.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill enables implicit invocation but does not define a narrowly scoped trigger condition, so the agent may auto-select this skill in situations broader than intended. That can cause unreviewed prompt injection of the skill’s instructions into unrelated conversations, leading to incorrect task routing, unexpected behavior, or leakage of user context to a skill that was not explicitly requested.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger sentence includes the generic phrase "Help me," which is common in ordinary user requests and can cause accidental activation of the skill outside its intended scope. In an agent system, overly broad invocation language increases the chance of misrouting requests, unexpected tool use, and leakage of irrelevant workflow behavior into unrelated conversations.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The invocation guidance is underspecified and does not clearly separate valid activation cases from normal conversation, which can lead to unintended or inconsistent skill invocation. This is especially risky because the skill's domain overlaps with common support and productivity language, making false positives more likely in real usage.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.