Back to skill

Security audit

Mobile Responsive Layout Fixer

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only skill for responsive layout help, with broad auto-invocation wording but no hidden execution, credential use, persistence, or unrelated data access.

Before installing, be aware that this skill may activate for fairly broad frontend or layout wording. It is otherwise a low-risk workflow skill; use explicit invocation when you want responsive layout help, and disable implicit invocation if your environment needs tighter routing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger sentence begins with a very broad conversational phrase ('Help me ...'), which can cause the skill to activate during ordinary user requests that were not meant to invoke this specific skill. In an agent environment, overly generic activation patterns increase the chance of unintended routing, prompt interference, or accidental execution of the wrong workflow.

Vague Triggers

Medium
Confidence
88% confidence
Finding
This trigger is ambiguous because 'I need a practical workflow for ...' is still a common natural-language request that may match many unrelated assistance scenarios. Ambiguous activation criteria can make skill selection unreliable and may invoke this skill when the user intended a different tool, especially in multi-skill agent systems.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are so generic that ordinary user requests about mobile UI, layout, or frontend help could invoke the skill unintentionally. This can cause skill overreach, route users into the wrong workflow, and create prompt-selection ambiguity that an attacker could abuse by crafting requests likely to hijack invocation.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger list includes very common terms such as "layout" and "frontend," which are likely to appear in many unrelated requests. This can cause unintended skill activation, leading the agent to route user requests into the wrong workflow and potentially override more appropriate or safer skills.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The example trigger phrases are broad, natural-language requests that can match ordinary conversation without strong scoping. Because they do not define clear boundaries for when the skill should activate, they increase the chance of accidental invocation and incorrect task routing.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger keywords include very broad terms such as "layout" and "frontend", which can match many unrelated user requests and cause the skill to activate outside its intended scope. Over-broad invocation increases the chance of misrouting user tasks, inappropriate context injection, or unintended execution of this skill when a more suitable skill should handle the request.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The usage condition is described very broadly, covering multiple vague categories and artifact types without clear boundaries for when the skill should or should not be used. This ambiguity can cause accidental triggering and unreliable skill selection, which is dangerous in an agent system because it expands the effective authority and reach of the skill beyond its narrowly intended purpose.

Vague Triggers

Low
Confidence
80% confidence
Finding
The example trigger phrases use generic natural-language formulations like "Help me" and "I need a practical workflow," which provide little constraint on when the skill should activate. In an automated routing environment, such examples can reinforce permissive matching behavior and increase false activations, though the direct security impact is lower than explicit broad trigger keywords.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The default prompt contains very broad trigger language tied to common terms like mobile responsive, responsive design, navbar, layout, workflow, checklist, analysis, and implementation support. Combined with allow_implicit_invocation: true, this can cause the skill to activate in many ordinary conversations where the user did not clearly intend to invoke it, increasing the risk of unintended prompt injection exposure, unnecessary context access, or inappropriate tool influence.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger sentences are highly generic and closely mirror ordinary user requests, which can cause the skill to activate unintentionally for broad frontend or design conversations. Over-broad activation increases the chance of context hijacking, inappropriate routing, or the skill being invoked when a narrower or safer workflow would be more appropriate.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.