Back to skill

Security audit

Error Message Improver

Security checks across malware telemetry and agentic risk

Overview

This skill is a documentation-only helper for improving error messages, with broad activation wording but no evidence of hidden execution, credential use, persistence, or destructive behavior.

Before installing, be aware that this skill may activate more often than expected for general debugging, support, or workflow wording. It appears safe as a writing/planning helper, but the publisher should narrow the triggers to explicit error-message improvement requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger sentences are generic enough to match many ordinary requests about productivity, debugging, support, or workflows, which can cause the skill to activate outside its intended scope. Over-broad activation increases the chance of prompt-routing mistakes, unexpected instruction injection into unrelated conversations, and user confusion when the agent applies this skill in contexts where it is not appropriate.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrases are extremely broad and map to common support and productivity requests, which can cause the skill to activate in many unrelated conversations. Overbroad activation increases the chance of prompt/skill hijacking at the routing layer, unintended invocation, and user confusion about why this skill was selected over safer or more specific alternatives.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The manifest description includes very broad activation language such as work-productivity, debugging, user feedback, support, and implementation support, which can match many ordinary user requests outside a narrowly defined skill boundary. This increases the chance of unintended invocation or over-selection, causing the skill to handle prompts it was not specifically designed to process and potentially interfering with safer or more appropriate routing.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger keywords include generic terms like debugging, support, troubleshooting, and user feedback that are common across many unrelated tasks. Overly broad triggers can cause accidental activation on benign conversations, expanding the skill's operational scope beyond its intended purpose and creating prompt-routing ambiguity or misuse opportunities.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger keywords are broad, generic terms like 'debugging', 'support', and 'user feedback' that commonly appear in unrelated conversations. This can cause the skill to activate outside its intended scope, leading to incorrect routing, user confusion, or untrusted automation being applied to normal requests without clear user intent.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill description defines when to use the skill with a wide list of loosely related categories, but does not clearly state exclusion criteria or boundaries. In agent systems, ambiguous activation criteria can cause overbroad invocation, unintended handling of user requests, and unsafe delegation of tasks to a skill that was not actually requested or appropriate.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The default prompt uses a broad, ambiguous invocation phrase ('Use $error-message-improver to help me...') without clear trigger boundaries or scoped conditions, which can cause the skill to be invoked in contexts beyond explicit user intent. Because implicit invocation is also enabled, this increases the chance of unintended activation, prompt routing errors, or overbroad handling of user input in ways that may expose data or produce unsafe automation behavior.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentence begins with a very broad everyday phrase ('Help me ...'), which can cause accidental or overly eager skill activation in normal conversation. In an agent environment, ambiguous activation can route unrelated user requests into this skill, causing unintended behavior, confusing outputs, or bypass of more appropriate tools and policies.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The sentence 'I need a practical workflow for ...' is still too generic and can match many unrelated productivity requests without clearly constraining the skill to error-message improvement tasks. This increases the chance of unintended invocation, especially because the skill is categorized broadly as work-productivity and support-oriented.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.