Back to skill

Security audit

Error Message Improver

Security checks across malware telemetry and agentic risk

Overview

The skill is a network-troubleshooting helper published under an error-message-improvement name, so users should review the mismatch before installing.

Install only if you intend to add a home-network diagnostics skill. The publisher should rename it and tighten triggers before broad use; as written, an agent may invoke it for unrelated error-message or general-help requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (14)

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The README content is materially inconsistent with the stated skill identity: it presents a network-diagnostics workflow while the skill is named 'Error Message Improver'. This kind of mismatch can cause incorrect invocation, mislead reviewers about the skill’s real purpose, and hide unauthorized or unexpected behavior behind misleading documentation.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill’s declared identity ('error-message-improver') does not match its actual behavior, which is network troubleshooting guidance. This mismatch can cause incorrect invocation, confuse operators and users, and undermine trust and review accuracy; in agent systems, mislabeled skills can route prompts to an unintended capability.

Intent-Code Divergence

Low
Confidence
90% confidence
Finding
The heading presents the skill as an error-message improver while the instructions describe a network-diagnostics assistant. Even if not directly exploitable for code execution, contradictory documentation increases the chance of misuse, poor oversight, and accidental activation in the wrong context.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The skill’s declared name and apparent purpose ('error-message-improver') do not match the body content, which is clearly a network-diagnostics workflow. This mismatch can cause incorrect routing, user confusion, and accidental invocation in contexts where the user did not intend networking guidance, weakening trust and safety review accuracy.

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
The skill metadata and requirement plan are materially misaligned: a skill named 'error-message-improver' is documented to handle network diagnostics, router issues, and bufferbloat workflows. This can cause incorrect routing or accidental invocation in unrelated contexts, leading users or downstream agents to disclose network details or receive unsafe/irrelevant guidance under a misleading capability label.

Intent-Code Divergence

Medium
Confidence
93% confidence
Finding
The usage documentation explicitly instructs invocation of the 'error-message-improver' skill for network troubleshooting requests, reinforcing the capability confusion rather than containing it. In multi-skill systems, this increases the chance that task selection, logging, and user expectations diverge from actual behavior, which can result in inappropriate data collection or execution paths.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are broad and generic, using terms like 'Help me' and 'I need a practical workflow', which can cause unintended activation outside the intended use case. In an agent environment, ambiguous triggers increase the risk that the wrong skill is selected, leading to unsafe context switching, user confusion, or execution of irrelevant instructions.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The manifest description includes broad terms like 'general-help' that are not tightly scoped to networking, increasing the chance that the skill activates for unrelated requests. Overbroad activation can expose users to irrelevant or unsafe guidance and interfere with correct skill selection.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger keyword list contains ambiguous everyday terms, especially 'general-help', that can match many unrelated user prompts. In an agent environment, broad trigger surfaces increase unintended invocation and can misroute user requests away from safer or more appropriate skills.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger keywords include broad, common terms such as 'general-help', 'router', 'modem', and 'latency', which are likely to appear in ordinary conversation. Overbroad activation increases the chance the skill is invoked unintentionally, causing prompt hijacking of unrelated conversations and unexpected behavior.

Vague Triggers

High
Confidence
95% confidence
Finding
The manifest description uses broad topical phrasing and open-ended conditions for use, making activation criteria ambiguous. This can cause the system to select the skill in unrelated contexts, exposing users to unintended instruction sets and reducing predictability of assistant behavior.

Natural-Language Policy Violations

Medium
Confidence
83% confidence
Finding
The file is written entirely in Chinese and does not state whether it is only for Chinese-speaking users or how language choice is handled. In multilingual environments, this can lead to silent misapplication, user confusion, and incorrect task execution if the skill activates for users expecting another language.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The default prompt invokes the skill with a very broad phrase and weak trigger constraints, which increases the chance of unintended or implicit activation for loosely related user requests. Because the policy also allows implicit invocation, this can cause the agent to steer conversations into this skill unexpectedly, potentially overriding user intent or exposing the system to prompt-scope confusion.

Vague Triggers

High
Confidence
91% confidence
Finding
The trigger phrases are broad natural-language prompts such as 'Help me...' and 'I need a practical workflow...', which are generic enough to match many benign conversations. Combined with the skill-purpose mismatch, this raises the risk of unintended activation, causing the wrong skill to intercept requests and potentially solicit or process unnecessary technical or network-related information.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.