Back to skill

Security audit

Software Data Admapix Raw Developer Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only helper with overly broad auto-activation wording, but no hidden code, credential use, persistence, or data-exfiltration behavior was found.

Before installing, consider narrowing or disabling implicit activation so the helper only runs for explicit AdMapix/raw-data workflow requests. The reviewed artifact itself is low impact and appears safe as a documentation helper.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger sentences are broad, natural-language phrases such as 'Help me' and 'I need a practical workflow', which can match ordinary user requests and cause unintended skill activation. In an agent environment, accidental activation can route user input into the wrong workflow, creating scope confusion and potentially causing the agent to process sensitive or unrelated tasks under this skill's instructions.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are broad enough to match ordinary user requests, which can cause this skill to activate outside its intended scope. In an agent ecosystem, overbroad routing can expose users to incorrect workflows, unintended data handling, or execution of a skill in contexts where safer or more appropriate skills should have been selected.

Vague Triggers

High
Confidence
96% confidence
Finding
The skill description and use conditions are broad enough to activate on very common terms like software, data, or implementation support, which can cause the wrong skill to be selected for unrelated requests. In an agent-routing context, overbroad matching can misroute user tasks, bypass more appropriate specialized safeguards, and increase the chance of unsafe or low-quality automation.

Vague Triggers

High
Confidence
99% confidence
Finding
The keyword list includes highly generic terms such as raw, data, layer, apps, and bug fix, which are likely to appear in many benign requests unrelated to this skill. This creates a strong risk of unintended invocation and prompt-space capture, where the skill can intercept broad classes of requests and influence downstream agent behavior outside its intended scope.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The example trigger sentences are vague and resemble ordinary user phrasing, without showing boundaries for when the skill should not run. This makes accidental invocation more likely and reinforces ambiguous routing behavior, especially when combined with the already broad description and keyword set.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger list includes very broad, common terms such as "raw", "data", "layer", and "apps", which can match many unrelated user requests and cause accidental invocation of this skill. In an agent environment, overbroad routing can misapply the skill's instructions or outputs to the wrong task, reducing reliability and potentially bypassing safer or more appropriate specialized skills.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill description says it should be used for broad categories like "software-and-data, admapix, raw, data, layer" or whenever the user needs a practical workflow, checklist, analysis, or implementation support for the requirement, but it does not define clear boundaries or exclusions. This ambiguity increases the chance that the skill is selected for tasks outside its intended scope, leading to incorrect guidance, workflow confusion, or unsafe handling of unrelated requests.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The default prompt uses a broad, natural-language trigger phrase ('help me') combined with a vague task description, which can cause unintended or overly broad invocation of the skill. Because implicit invocation is enabled, the skill may activate in unrelated contexts and influence agent behavior without clear user intent or tight scope boundaries.

Vague Triggers

High
Confidence
91% confidence
Finding
The trigger sentence begins with an extremely broad phrase ('Help me ...'), which can cause the skill to activate for many unrelated user requests. Overbroad activation increases the chance of prompt hijacking at the routing layer, accidental invocation in the wrong context, and delivery of this skill when another safer or more specific skill should handle the request.

Vague Triggers

High
Confidence
89% confidence
Finding
The phrase 'I need a practical workflow for ...' is a vague generic request pattern that matches ordinary requests across many domains, not just this skill's intended scope. In a skill-routing system, this can lead to misrouting, unintended execution paths, and expanded attack surface because unrelated prompts may be captured by this skill.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.