Back to skill

Security audit

Error Message Improver

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only skill for improving error messages, with no hidden execution, credential use, persistence, or destructive behavior found.

Install only if you want an assistant workflow focused on rewriting or designing clearer application error messages. Be aware that its broad keywords may make it appear for some general debugging or support requests, so explicit invocation is preferable when using it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger sentences are broad enough to match ordinary requests about debugging, support, and workflow help, which can cause the skill to activate in situations beyond its narrow intended use. Over-broad activation increases the chance of unintended interception of user requests and may steer users into this skill when another, more appropriate workflow should handle the task.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger phrases are broad enough to match common support, debugging, and productivity requests, which can cause the skill to activate outside its narrowly intended context. Over-broad activation increases the chance that the skill intercepts unrelated user requests and influences responses unexpectedly, creating routing and prompt-scope risk even though the file itself does not contain direct code execution or exfiltration behavior.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The manifest description includes very broad activation cues such as work-productivity, debugging, user feedback, support, and practical workflow requests, which can match a wide range of unrelated user intents. Over-broad routing can cause the skill to activate outside its intended scope, leading to irrelevant guidance, prompt interference with more appropriate skills, and increased attack surface for adversarial triggering.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The trigger keywords are highly generic, especially debugging, support, troubleshooting, and user feedback, so the skill may be invoked for many requests that are not actually about error-message improvement. This increases the likelihood of unintended activation, which can misroute conversations, degrade system reliability, and make it easier to deliberately force this skill into contexts where it does not belong.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger keywords are very broad terms like work-productivity, debugging, support, and troubleshooting, which commonly appear in ordinary user requests. This can cause unintended activation of the skill in contexts where the user did not explicitly want it, increasing the chance of irrelevant guidance, prompt-routing errors, or accidental exposure of internal workflow behavior.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The example trigger phrases are written in broad everyday language and effectively encourage activation from generic requests for help or workflows. Because these examples shape invocation behavior, they can lead to over-triggering in normal conversations and reduce predictability of tool/skill selection, especially in support and debugging contexts where such wording is common.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The default prompt uses a very broad, natural-language invocation phrase ('Use $error-message-improver to help me...') that can match ordinary user requests about error messages, debugging, support, or workflow help. Combined with implicit invocation, this increases the chance the skill is triggered unintentionally, causing prompt-scope expansion or routing of user data/context into the skill when the user did not explicitly request it.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger sentence begins with a very broad everyday request pattern ('Help me ...'), which can cause the skill to activate during normal conversation even when the user did not intend to invoke this specific capability. Overbroad activation increases the chance of unintended routing, prompt capture, or interference with other skills, especially in a support/debugging context where similar phrasing is common.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger sentence uses a generic request template ('I need a practical workflow for ...') without clear activation boundaries, making it ambiguous and likely to match unrelated user requests. This can lead to accidental invocation, misrouting of user intent, and reduced trust in agent behavior because ordinary planning requests may activate the skill unexpectedly.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.