Back to skill

Security audit

Error Message Improver

Security checks across malware telemetry and agentic risk

Overview

This skill is a documentation-only helper for improving error messages, with no executable code, persistence, or data access, though its activation wording is broader than ideal.

Installers should know this skill may be invoked for broad debugging or support phrasing, not only explicit error-message rewrites. If installed, prefer explicit use for improving user-facing errors and consider narrowing trigger text or disabling implicit invocation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger sentences are broad, natural-language phrases such as 'Help me' and 'I need a practical workflow', which are common in ordinary user conversations. This can cause unintended skill activation, leading the agent to invoke this skill when the user did not explicitly request it, potentially altering behavior or exposing internal workflows unexpectedly.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases are broad enough to match ordinary requests about productivity, debugging, support, and troubleshooting, which can cause the skill to activate outside its intended scope. Over-broad activation increases the chance of inappropriate routing, prompt hijacking opportunities through unrelated contexts, or unexpected handling of sensitive user requests.

Vague Triggers

High
Confidence
94% confidence
Finding
The manifest description contains very broad activation cues like 'Help users with' and a wide set of common intents, which can cause the skill to match many unrelated requests. Over-broad routing increases the chance the agent invokes this skill outside its intended scope, creating prompt-surface expansion and possible interference with more appropriate, safer, or narrower skills.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger keywords include generic terms such as 'debugging', 'support', and 'troubleshooting' without scope constraints, so ordinary requests could spuriously activate this skill. That makes tool selection less reliable and may expose users to irrelevant instructions or displace better-matched skills.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example trigger starts with 'Help me', a very common conversational phrase that collides with everyday speech and lowers activation precision. Even if only illustrative, examples often influence routing heuristics or developer usage patterns, increasing accidental invocation frequency.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger conditions are broad enough to match many generic troubleshooting, support, and productivity requests, which can cause the skill to activate outside its intended narrow use case. Overbroad activation increases the chance of prompt hijacking at the routing layer, user confusion, and unintended precedence over more appropriate skills, especially because the skill claims authority over common support/debugging scenarios.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill enables allow_implicit_invocation without any narrowly scoped activation guard, which can cause the agent to invoke this skill based on broad contextual matches rather than explicit user intent. Because the skill is broadly described around debugging, support, workflow, and implementation help, it could be triggered in unintended contexts and process sensitive error, system, or support content, increasing the risk of overreach, data exposure, or confusing autonomous behavior.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentence begins with a very broad everyday phrase ('Help me ...'), which can cause the skill to activate during ordinary user requests that were not intended to invoke this specific skill. In an agent system, overly broad activation increases the chance of unintended routing, causing irrelevant behavior, prompt/context leakage into the wrong workflow, or user confusion during support and debugging tasks.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The sentence 'I need a practical workflow for ...' is still generic and could match many unrelated productivity or analysis requests, making activation insufficiently constrained. While not overtly malicious, this ambiguity can lead to accidental invocation and misapplication of the skill in contexts outside error-message improvement.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.