Back to skill

Security audit

Error Message Improver

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only skill for improving error messages, with broad activation wording but no hidden commands, credential use, persistence, or data export.

Before installing, be aware that this skill may be selected for broad debugging or support requests, not only explicit error-message rewriting. That could be mildly distracting, but the inspected files do not show hidden execution, credential handling, persistence, or exfiltration behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger sentences are broad enough to match routine requests about debugging, support, or productivity, which can cause the skill to activate outside a clearly scoped user opt-in. Overbroad activation increases the chance of unintended instruction injection into unrelated conversations and may override more appropriate, narrower skills.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrases are broad enough to match routine requests about productivity, debugging, or support, which can cause the skill to activate outside its intended scope. Over-broad activation is dangerous because it can unexpectedly steer unrelated conversations, inject workflow behavior where not wanted, and increase the chance that other safeguards or more appropriate skills are bypassed.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The manifest description includes very broad activation language such as general work-productivity, debugging, support, and implementation-help terms. In skill-routing systems, this can cause the skill to activate for many unrelated user requests, increasing the chance of incorrect tool selection, prompt-scope capture, and unintended handling of conversations outside the skill’s intended domain.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The trigger keywords are generic and high-frequency terms that appear in many unrelated conversations. This makes activation unreliable and can lead to over-triggering, where the skill intercepts broad troubleshooting or support requests that do not actually involve rewriting or improving error messages.

Vague Triggers

Low
Confidence
91% confidence
Finding
The example triggers use everyday phrasing that is still broad enough to match common requests, and they do not clearly distinguish this skill from general workflow or troubleshooting assistance. Although less severe than the manifest and keyword issues, these examples reinforce ambiguous routing behavior and increase the probability of accidental invocation.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger keywords are very broad and common terms such as work-productivity, debugging, support, and troubleshooting, which can cause the skill to activate in many unrelated contexts. Over-broad activation increases the chance that the agent applies this skill when it is not appropriate, leading to confusing behavior, incorrect workflow injection, or overshadowing more suitable skills.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The description states the skill should be used for broad categories like work-productivity, debugging, user feedback, and support, without clearly limiting it to error-message improvement tasks. This ambiguity can make routing logic select the skill for generic assistance requests, creating prompt-scope confusion and increasing the risk of irrelevant or misleading outputs.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill enables implicit invocation while providing only a broad, generic description of when it should be used. This increases the chance the agent will auto-select the skill in unrelated contexts, causing unintended prompt injection of the skill’s instructions into conversations and expanding the attack surface for misuse or data exposure.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger sentence begins with an extremely broad everyday phrase ('Help me ...'), which can cause the skill to activate during ordinary user requests that are not intended to invoke this capability. In an agent environment, overbroad activation increases the chance of unintended routing, prompt-context contamination, and accidental execution of workflows on unrelated conversations.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger sentence is too generic and does not clearly define when the skill should versus should not activate. Ambiguous activation scope can lead to misfires where unrelated productivity or support requests invoke this skill, producing incorrect assistance and exposing downstream systems to unnecessary prompt injection surface from irrelevant context.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.