Back to skill

Security audit

Error Message Improver

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only skill for improving error messages, with some overly broad activation wording but no hidden execution, persistence, credential access, or destructive behavior.

This skill is reasonable to install if you want help rewriting or structuring error messages. Be aware that its broad trigger terms may cause it to appear during general debugging or support conversations, so invoke a more specific skill or disable implicit use if routing precision matters.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger sentences are broad enough to match many normal support, debugging, and productivity requests, which can cause the skill to activate unexpectedly. Over-broad activation increases the chance of unintended instruction injection into unrelated conversations and can bypass user intent by steering responses into this skill when it was not explicitly requested.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrases and keywords are broad enough to match many ordinary support, productivity, or debugging requests, which can cause the skill to activate outside its intended scope. Over-broad activation is dangerous because it increases prompt-injection surface and may cause the agent to prioritize this skill in unrelated contexts, leading to inappropriate handling or policy bypass through skill routing confusion.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill description is broad enough to match many ordinary requests about productivity, debugging, support, and implementation help, which increases the chance of unintended auto-invocation. Overbroad routing can cause the wrong skill to activate, leading to prompt-context contamination, user confusion, and expanded exposure of downstream tools or instructions beyond what was necessary.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The trigger keywords are highly generic terms that appear in a large volume of normal conversations, so the skill may activate when the user did not actually request error-message improvement. This makes the skill more dangerous in context because it is framed as a broadly applicable workflow and artifact generator, increasing the likelihood of misrouting and unnecessary instruction injection into unrelated tasks.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description is broad enough to activate on very common requests like debugging, support, or user feedback without strong scope constraints. Overly generic triggers can cause unintended invocation, leading the agent to apply this skill in unrelated contexts and potentially override more appropriate, safer, or domain-specific handling.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The keyword list uses highly generic terms like 'debugging', 'support', and 'troubleshooting' without qualifiers, which increases the chance of accidental matching across many unrelated user requests. This can broaden the skill's execution surface and create prompt-routing errors, especially in systems that auto-select skills from keyword matches.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The default prompt is vague and broadly phrased, which can cause the skill to be invoked in situations beyond its intended scope. Because implicit invocation is enabled, this ambiguity increases the chance of accidental activation on loosely related user requests, potentially leading to irrelevant behavior, prompt-surface expansion, or unintended handling of sensitive troubleshooting content.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentence is so broad and generic that it can match ordinary user requests unrelated to this skill, causing unintended invocation. That can misroute user intent, override more appropriate skills, and create unsafe behavior if the agent applies this workflow in contexts where it was not explicitly requested.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.