Back to skill

Security audit

Error Message Improver

Security checks across malware telemetry and agentic risk

Overview

This is a low-risk documentation skill for improving error messages, with no executable code or hidden data access, though its activation wording is broader than ideal.

Installers should understand that this skill is safe in capability terms but may be invoked too broadly. Prefer explicit use for rewriting or improving error messages, and consider tightening triggers before publishing widely.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger sentence is phrased as a very broad natural-language request ('Help me ...'), which increases the chance the skill is invoked unintentionally during ordinary conversation. Unintended invocation can route user input into the wrong workflow, causing confusing behavior, poor task isolation, and accidental processing of content that was not meant for this skill.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The README lists only broad example triggers and does not clearly specify when the skill should or should not activate. This ambiguity makes over-triggering more likely, especially because the skill targets common topics like debugging, support, and error messages that frequently appear in normal user requests.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are extremely broad and map to common support and productivity requests, which can cause the skill to activate in many unrelated conversations. That increases the chance of unintended routing, overriding more appropriate skills, and creating prompt-scope confusion that could be abused for instruction capture or misapplication.

Vague Triggers

High
Confidence
96% confidence
Finding
The skill description uses very broad routing terms like work-productivity, debugging, support, and implementation support, which can cause the skill to activate for many unrelated requests. Overbroad activation is dangerous because it can hijack user intent, interfere with more appropriate skills, and increase the chance that adversarial or irrelevant instructions are injected into otherwise unrelated conversations.

Vague Triggers

High
Confidence
98% confidence
Finding
The trigger keywords are generic everyday terms such as debugging, support, troubleshooting, and user feedback, which overlap heavily with normal assistant usage. This makes unintended invocation likely at routing time, expanding the skill's influence beyond its intended domain and potentially suppressing safer or more specialized handling.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The example trigger sentences begin with highly generic phrases like 'Help me' and 'I need a practical workflow', which can train or bias invocation systems toward matching on weak, non-specific language. This increases accidental activation and makes the skill easier to invoke in contexts unrelated to error-message improvement, reducing routing integrity.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger keywords are very broad and overlap with common support and productivity language, making accidental invocation plausible during ordinary conversations. This can cause the agent to enter this skill unexpectedly, producing irrelevant workflow behavior and reducing reliability; while not a direct code-execution issue, it is a genuine security/control-plane concern because overly permissive routing can be abused or can override safer/default handling.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The example trigger phrases are generic everyday requests and do not enforce strong activation constraints, which trains or encourages invocation on ambiguous user input. In practice this increases the chance of misrouting prompts into this skill, potentially exposing unrelated user requests to inappropriate transformations or causing the agent to follow the wrong operational workflow.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The default prompt is broad and loosely phrased, while implicit invocation is enabled, making it easier for unrelated user requests about debugging, support, or productivity to trigger this skill unintentionally. That can cause prompt-routing confusion, unexpected disclosure of user context to the skill, or execution of the wrong workflow, which is a real security and reliability issue even though the skill itself is not obviously malicious.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger sentence is so generic that it can match ordinary user requests unrelated to this specific skill, causing unintended activation. That increases the chance the agent applies this workflow in the wrong context, leading to prompt-routing errors, user confusion, and possible leakage of irrelevant guidance into sensitive support or debugging conversations.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The invocation guidance does not define clear boundaries for when the skill should and should not run, and the listed triggers are broad enough to overlap with common debugging, support, and productivity language. In an agentic environment, ambiguous routing can cause this skill to intercept general requests, produce mis-scoped outputs, and interfere with more appropriate skills or security-sensitive handling paths.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.