Back to skill

Security audit

Error Message Improver

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only skill for improving error messages, with overly broad activation wording but no executable code, persistence, credential use, or hidden data access.

Install only if you want an agent to help rewrite or structure error and troubleshooting messages. Be aware it may be selected for some general debugging or support requests because the trigger terms are broad; explicit invocation is safer for precise use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrases are generic enough to match ordinary help-seeking language, which can cause the skill to activate unexpectedly in unrelated conversations. Over-broad activation is dangerous because it can hijack routing or inject the skill's workflow when the user did not explicitly request it, increasing the chance of inappropriate guidance, prompt-surface expansion, or interference with safer/default handling.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrases are broad, natural-language prompts that can match many ordinary support or productivity requests, causing the skill to activate outside its intended scope. Over-broad activation increases the chance that users are routed into this skill unexpectedly, which can override more appropriate skills or cause unintended processing of unrelated requests.

Vague Triggers

High
Confidence
92% confidence
Finding
The skill description uses very broad activation terms like work-productivity, debugging, user feedback, support, and implementation support, which can cause the agent to invoke this skill for many routine requests outside its narrow purpose. Over-broad routing increases the chance that this skill captures unrelated conversations, leading to prompt-scope drift, unnecessary exposure of user context, and interference with safer or more appropriate skills.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger keywords and example phrases are highly generic and lack guardrails, so ordinary requests about debugging, support, troubleshooting, or user feedback may activate the skill even when the user is not asking for error-message improvement. This broad matching can misroute agent behavior, causing inappropriate workflow injection and reducing reliability of task selection across the skill system.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger keywords are very broad and include common, high-frequency topics such as debugging, support, and user feedback. This can cause the skill to activate in many unrelated conversations, creating prompt-routing risk where the model applies this skill outside its intended scope and may override more appropriate instructions or workflows.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example trigger phrases begin with highly generic formulations like 'Help me' and 'I need a practical workflow,' which are common across many benign requests. If used by an agentic router or matching system, these examples can overfit the invocation logic and increase accidental activation, causing unintended context injection or misrouting.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill enables implicit invocation without any visible trigger constraints, which can cause the agent to activate in situations broader than intended. That increases the chance the skill is applied to unrelated user requests, potentially shaping outputs or workflows unexpectedly and expanding the attack surface for prompt-routing abuse.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger sentence begins with the generic phrase "Help me," which is common in ordinary conversation and not sufficiently scoped to this skill’s specific function. That increases the chance of accidental invocation in unrelated contexts, causing the agent to route tasks to this skill when the user did not intend to use it.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.