Back to skill

Security audit

Error Message Improver

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only helper for improving error messages, with overly broad activation wording but no hidden code, data access, persistence, or privileged behavior.

Install only if you want a broad assistant for improving error messages and related support workflows. Consider tightening the trigger wording or disabling implicit invocation to avoid accidental activation on general support or debugging requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger sentence is phrased as a very general natural-language request and closely mirrors ordinary user help text, which can cause the skill to activate unintentionally in unrelated conversations. In an agent environment, over-broad activation increases the chance of prompt/context hijacking at the routing layer, where the wrong skill is invoked and influences outputs unexpectedly.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The activation guidance does not define clear boundaries for when the skill should or should not run, so ordinary requests about debugging, support, or workflow could ambiguously match. In a multi-skill agent system, this ambiguity can lead to unintended invocation, misrouting, and inappropriate instruction injection from the skill into contexts where it was not requested.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger phrases are extremely generic and closely match ordinary support or productivity requests, which can cause the skill to activate in situations far beyond its intended scope. Over-broad activation increases the chance of prompt/context interception, unintended routing, or inappropriate transformation of unrelated user requests.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The manifest description uses very broad activation terms like work-productivity, debugging, support, workflow, artifact, checklist, analysis, and implementation support. In agent routing systems, this can cause the skill to be invoked for many ordinary requests outside its narrow purpose, increasing the chance of unintended instruction capture or priority over more appropriate skills.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The trigger keywords are highly generic and common in normal conversation, especially debugging, support, troubleshooting, and user feedback. Generic triggers increase collision risk, causing accidental activation and exposing the model to irrelevant instructions or cross-skill interference in contexts unrelated to error-message improvement.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The example triggers are phrased as broad everyday requests and even include an explicit skill invocation form, which may train routing or users to activate the skill for loosely related tasks. Overbroad examples reinforce imprecise matching behavior and make unintended activation more likely across many benign support or productivity requests.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger section uses broad generic keywords such as work-productivity, debugging, support, and troubleshooting, plus example invocations that match many ordinary user requests. This can cause the skill to activate outside its intended scope, leading to overbroad interception of requests and unintended influence on task routing or response generation.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The top-level description says the skill should be used for broad categories like work-productivity, debugging, user feedback, and support, but does not define concrete boundaries or exclusions. Ambiguous enablement language increases the chance of accidental invocation on unrelated tasks, which may create prompt-routing confusion and reduce reliability of the agent's behavior.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The default prompt uses a very broad invocation phrase tied to a wide set of generic user intents, which can cause the skill to be invoked in contexts the user did not explicitly request. Because implicit invocation is also enabled, this increases the chance of prompt overreach, unintended routing, or the skill influencing unrelated conversations without clear user consent.

Vague Triggers

High
Confidence
92% confidence
Finding
The trigger sentence is so broad and conversational that it can match ordinary user requests unrelated to this specific skill, causing unintended activation. In an agent system, this can misroute prompts, override more appropriate skills, and create prompt-scope confusion that weakens safety and predictability.

Vague Triggers

Medium
Confidence
89% confidence
Finding
This trigger phrase lacks concrete activation boundaries and effectively allows the skill to claim a wide class of generic workflow requests. That ambiguity increases the chance of accidental invocation and skill overreach, which is especially risky in orchestration systems where routing decisions may be made automatically from natural language.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.