Back to skill

Security audit

Error Message Improver

Security checks across malware telemetry and agentic risk

Overview

This skill is a low-risk writing/workflow helper for clearer error messages, but its trigger wording is broad and may activate more often than users expect.

Before installing, be aware that the skill may be selected for general debugging or support requests because its triggers are broad. It appears safe as a writing and workflow aid, but users who want precise routing should narrow the trigger wording or disable implicit invocation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger sentences are broad enough to match ordinary requests about debugging, support, or practical workflows, which can cause the skill to activate in many unrelated contexts. Over-broad activation increases the chance of unintended prompt injection surface, misrouting, or the skill steering conversations when the user did not explicitly request it.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are broad enough to match ordinary user requests for help with debugging or support, which can cause the skill to activate in situations where the user did not explicitly intend to invoke it. Over-broad activation increases the chance of inappropriate routing, prompt hijacking of normal conversations, or accidental application of the skill’s workflow to unrelated tasks.

Vague Triggers

High
Confidence
95% confidence
Finding
The skill description is broad enough to match many ordinary support, debugging, and productivity requests without clear boundaries. Over-broad routing can cause this skill to activate inappropriately, crowd out more specific skills, and increase the chance that users receive generic or mis-scoped guidance.

Vague Triggers

High
Confidence
97% confidence
Finding
The keyword list uses generic terms like 'debugging', 'support', and 'user feedback' that appear in a wide range of unrelated requests. This makes accidental invocation likely and can be abused for prompt-routing hijack, where this skill intercepts requests better handled by safer or more specialized skills.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The example triggers are written in very generic everyday language and do not establish clear activation boundaries. This reinforces ambiguous routing behavior and teaches the system to invoke the skill for loosely related requests, increasing confusion and reducing reliability.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger section uses broad, common terms like 'debugging', 'support', and 'user feedback' without clear scoping constraints, so the skill may activate for many ordinary requests outside its intended niche. This can cause inappropriate routing or overuse of the skill, reducing reliability and potentially steering users into workflows or outputs they did not request.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The default prompt is framed with very broad, natural-language wording around common support and productivity tasks, which can overlap with ordinary user speech and cause accidental routing to this skill. In combination with agent ecosystems that auto-select skills, this increases the chance of unintended invocation and prompt-scope expansion, especially because the skill description itself is broad and task-oriented.

Vague Triggers

Medium
Confidence
97% confidence
Finding
Enabling implicit invocation without strong trigger boundaries allows the platform to auto-activate the skill based on ambiguous conversational cues. Given this skill's broad domain description around debugging, support, feedback, workflows, and implementation help, unintended activation is more likely and could interfere with user intent, expose extra context to the skill, or let the skill influence responses when not explicitly requested.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger sentence uses a very broad, natural-language phrase ('Help me ...') that is likely to appear in ordinary user requests. This can cause unintentional invocation of the skill in contexts where the user did not explicitly want this behavior, increasing the chance of prompt routing mistakes, irrelevant task execution, or interference with other skills.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The invocation guidance is too generic and does not define clear activation boundaries, so the orchestrator may match this skill on loosely related requests involving support, debugging, or productivity. In this skill context, that broad scope is more dangerous because the metadata and usage signals already cover common everyday troubleshooting language, making accidental invocation materially more likely.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.