Back to skill

Security audit

Software Data Admapix Raw Developer Helper

Security checks across malware telemetry and agentic risk

Overview

This is a low-privilege workflow helper with overly broad activation wording, but it does not install code, persist, access credentials, exfiltrate data, or perform hidden actions.

Install only if you want a general AdMapix-style software/data workflow helper. Be aware it may activate on broad software or data phrasing, so explicitly name a different skill or workflow when you do not want this helper used.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger sentences are broad, natural-language phrases that overlap with ordinary user requests, which can cause the skill to activate when the user did not explicitly intend to invoke it. In an agent ecosystem, unintended invocation can route tasks into the wrong workflow, increasing the chance of inappropriate actions, confusing outputs, or accidental processing under this skill's assumptions.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrases are broad, generic, and partially map to common support requests such as needing a practical workflow or help fixing bugs. This can cause accidental invocation of the skill in unrelated contexts, increasing the chance that the agent routes users into unintended workflows or exposes outputs not scoped to the user's actual intent.

Vague Triggers

High
Confidence
94% confidence
Finding
The skill description and usage guidance are broad enough to match many ordinary software or data requests, which can cause the skill to activate outside its intended scope. Over-broad activation increases the chance that irrelevant or lower-safety-reviewed instructions are injected into unrelated conversations, reducing routing accuracy and potentially bypassing more appropriate specialized skills.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger keywords include highly generic terms such as 'raw', 'data', 'layer', 'apps', and 'bug fix', which are likely to appear in many unrelated requests. This creates a high risk of accidental invocation, causing prompt-scope confusion and inappropriate tool or workflow guidance to be applied where it does not belong.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example trigger sentences use everyday phrasing and repeat a generic requirement statement instead of demonstrating crisp activation boundaries. This can train routing systems or authors to invoke the skill on vague requests, increasing false activations and making it harder to distinguish when the skill is actually appropriate.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger keyword list is overly broad and includes generic terms such as 'raw', 'data', 'layer', 'apps', and 'bug fix' that commonly appear in unrelated conversations. This can cause accidental invocation of the skill outside its intended AdMapix-specific context, leading to prompt-routing confusion and inappropriate handling of user requests.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example trigger sentences use very generic phrasing like 'Help me' and 'I need a practical workflow', which overlaps heavily with normal user language. If these examples are used by routing or retrieval systems as activation cues, the skill may be selected for many unrelated requests, increasing the risk of misrouting and unintended instruction application.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The default_prompt is broad and generic enough to trigger the skill in contexts beyond a clearly scoped AdMapix/raw-data developer workflow. Combined with allow_implicit_invocation: true, this increases the chance of unintended activation, causing the agent to apply this skill in unrelated requests and potentially expose users to incorrect automation, over-broad actions, or hidden prompt influence.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger examples are so broad and awkwardly templated that normal user requests containing generic phrases like 'help me' or 'I need a practical workflow' plus loose keyword overlap could activate this skill unintentionally. In an agent-routing context, overbroad invocation can misroute tasks, expose the user to irrelevant or lower-quality actions, and increase the chance that a more privileged or less appropriate skill handles the request.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The activation examples do not clearly delimit when this skill should or should not run, and they include truncated, repetitive boilerplate rather than concrete boundaries. Ambiguous trigger scope is dangerous because agent systems may over-select this skill for unrelated software/data tasks, causing unintended execution paths, poor task isolation, and possible chaining into workflows the user did not intend.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.