Back to skill

Security audit

Error Message Improver

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only skill for improving error messages, with broad activation wording but no hidden execution, credential use, persistence, or data exfiltration behavior.

Installers should be aware that this skill may activate for broad debugging or support prompts, so explicit invocation is preferable when the user specifically wants error-message wording or troubleshooting-copy help. No evidence was found of hidden execution, data collection, credential use, or destructive behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are broad, natural-language requests such as 'Help me' and 'I need a practical workflow', which can cause the skill to activate in contexts far beyond narrowly scoped error-message improvement. Overbroad activation increases the chance of prompt/skill hijacking, unintended routing, or the skill being invoked on unrelated sensitive tasks where its instructions may distort handling or override more appropriate safeguards.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases are broad enough to match many routine requests about debugging, support, and productivity, which can cause the skill to activate outside its intended scope. In an agent ecosystem, overbroad invocation increases the chance of inappropriate routing, unexpected prompt injection exposure, or the skill influencing unrelated tasks.

Vague Triggers

High
Confidence
93% confidence
Finding
The skill description is broad enough to match many common support and productivity requests, which can cause the skill to activate outside its intended scope. Unintended invocation is dangerous because it can override more appropriate skills, create confusing agent behavior, and increase the chance that untrusted instructions in the skill are applied in irrelevant contexts.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The trigger keywords are highly generic terms like 'debugging', 'support', and 'user feedback', which are common across many unrelated tasks. This makes accidental activation likely and can route conversations into this skill when the user did not request error-message improvement, degrading safety and reliability through scope confusion.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger section uses very broad, common keywords such as 'debugging', 'support', and 'user feedback' without strong scoping constraints. This can cause the skill to activate in many unrelated contexts, leading to unintended invocation, response hijacking, or overshadowing of more appropriate skills.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description says it should be used whenever users need practical workflows, artifacts, checklists, analysis, or implementation support around the requirement, which is overly broad and weakly bounded. In a skill-routing system, this creates prompt-scope ambiguity and raises the chance that the skill is selected for generic productivity or support tasks beyond its intended function.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill enables implicit invocation but does not define a narrowly scoped trigger, so the agent may activate in response to broad, ambiguous user requests. In this context, that can cause the skill to engage unexpectedly in general debugging, support, or productivity conversations, increasing the chance of overreach, prompt-surface expansion, or unintended handling of user content.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The default prompt uses broad everyday-language terms such as work-productivity, debugging, support, and practical workflow assistance, which substantially widens the range of prompts that may match this skill. Combined with implicit invocation, this creates a realistic risk that the skill is selected outside its intended purpose, leading to unintended actions, irrelevant transformations, or exposure of sensitive troubleshooting context.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentence is so broad and natural-language-like that it can match ordinary user requests unrelated to explicit skill invocation. This can cause the skill to activate unexpectedly, influencing responses outside its intended scope and potentially overriding more appropriate handling paths.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The activation guidance does not define clear boundaries for when the skill should and should not run, and the listed keywords are common across many benign conversations. Poor trigger scoping increases the chance of unintentional routing, which can degrade reliability, leak contextual influence into unrelated tasks, and make downstream behavior harder to predict or audit.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.