Back to skill

Security audit

Mobile Responsive Layout Fixer

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only responsive-layout helper skill with broad auto-invocation wording but no hidden code, credential access, persistence, or destructive behavior.

Before installing, be aware that this skill may activate for general frontend or layout requests because its triggers are broad. It appears safe from a security standpoint, but the publisher should narrow the trigger wording if precise routing matters.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger sentences are generic enough that normal conversation about mobile layouts or practical workflows could invoke the skill unintentionally. In an agent system, overbroad activation can route users into an unintended workflow, causing confusing outputs, context leakage across tasks, or execution of the wrong automation path even if the skill itself is not overtly harmful.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrases are extremely broad and include generic terms like 'layout', 'frontend', and natural-language prompts that could cause the skill to activate in contexts the user did not intend. In an agent ecosystem, over-broad invocation increases the chance of prompt-routing mistakes, accidental execution, and inappropriate application of the skill to unrelated requests.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger keywords are broad enough to match common frontend and design requests such as 'layout' or 'frontend', which can cause this skill to activate outside its intended scope. Overbroad activation increases the chance of prompt-routing mistakes, irrelevant instructions being injected into unrelated tasks, and accidental disclosure or modification of user workflows.

Vague Triggers

Low
Confidence
80% confidence
Finding
The example trigger sentences are vague and formulaic, encouraging activation from unnatural phrases rather than clearly bounded user intent. This can train or bias invocation logic toward loose matching, making accidental or inappropriate skill selection more likely in normal conversations.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger keywords are broad enough to overlap with ordinary frontend discussions, which can cause the skill to activate in contexts where the user did not intend to invoke a specialized workflow. In an agent setting, over-broad activation can steer conversations, produce irrelevant actions, or mask better-matched skills, creating reliability and prompt-routing risk even without malicious content.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The usage condition in the description is overly general and does not clearly define boundaries for when the skill should or should not be used. This increases the chance of accidental invocation across a wide class of creative or frontend requests, which can degrade agent behavior and lead to inappropriate handling of user tasks.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill enables implicit invocation without any visible bounded activation criteria, which can cause the agent to auto-select this skill for loosely related prompts. That increases the chance of unintended routing, prompt-surface expansion, and execution of skill-specific behavior when the user did not explicitly request it.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger sentences are broad enough to match ordinary user phrasing such as 'help me' or 'I need a practical workflow,' which can cause unintended invocation of the skill. Over-broad activation increases the chance that the agent applies this skill in unrelated contexts, potentially steering outputs away from user intent or bypassing more appropriate safeguards and tools.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.