Back to skill

Security audit

Error Message Improver

Security checks across malware telemetry and agentic risk

Overview

This prompt-only skill helps improve error messages and does not ask for sensitive access, though its activation wording is broader than necessary.

Installers should expect this skill to influence how an agent writes error messages and troubleshooting copy. Consider narrowing its trigger phrases if you want it used only for explicit error-message improvement tasks, but there is no evidence of hidden access, data collection, persistence, or destructive actions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger sentences are generic enough to match ordinary support, debugging, and productivity requests, which can cause the skill to activate outside its intended scope. Over-broad activation increases the chance that the skill intercepts unrelated conversations, influences outputs unexpectedly, or crowds out safer/more appropriate skills, especially in automated routing systems.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrases are broad enough to match many ordinary requests about productivity, debugging, support, or feedback, which can cause the skill to activate outside its intended scope. Over-broad activation increases the chance of inappropriate routing, prompt hijacking opportunities through unrelated contexts, and unexpected handling of user data or workflows.

Vague Triggers

High
Confidence
92% confidence
Finding
The description says to use the skill for broad categories like work-productivity, debugging, user feedback, support, and implementation support, which can match many unrelated requests and cause over-invocation. In an agent system, overly broad routing increases the chance this skill is selected outside its intended scope, leading to prompt-surface expansion and unintended handling of requests.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger keywords are highly generic terms that appear in many ordinary conversations, so they can activate the skill for requests that are not actually about error-message improvement. This broadens the attack and misrouting surface, especially in automated tool-selection pipelines that rely on keyword overlap.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger section provides positive examples but no activation boundaries or negative examples, so the agent lacks guidance on when not to invoke the skill. Without explicit exclusions, common support or debugging prompts may incorrectly route here, causing confusion, unnecessary tool use, or interference with more appropriate skills.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger keywords and example invocations are broad enough to overlap with many ordinary support or productivity requests, which can cause the skill to activate unintentionally. While this is not an exploit primitive by itself, accidental invocation can misroute user intent, suppress better-matched skills, or cause confusing behavior in mixed-skill environments.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill enables implicit invocation without any trigger phrases, topical boundaries, or scope constraints, which allows the agent to invoke it in a broad range of contexts. Because this skill influences error messages and support/debugging workflows, unintended activation could cause prompt-routing confusion, over-application to unrelated tasks, or adversarial steering through crafted user input that causes the skill to be invoked when it should not be.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger sentence is so generic that normal user requests like 'Help me' or similarly broad productivity asks could unintentionally invoke this skill outside its intended scope. Because the skill is about error-message improvement and support workflows, accidental activation could route unrelated conversations into the wrong workflow, causing confusing behavior, over-collection of context, or misuse of outputs in places the user did not intend.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.