Back to skill

Security audit

Software Data Admapix Raw Developer Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only developer workflow helper with no executable code, persistence, credential handling, or hidden data access, though its activation wording is overly broad.

Install only if you want a broad developer/workflow helper for AdMapix-style raw data or adjacent skill-design tasks. Expect possible accidental activation on generic data or bug-fix requests; review outputs for relevance before applying any suggested code or workflow changes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrases are extremely broad and effectively match generic requests for 'practical workflow' or bug-fixing help, which can cause the skill to activate outside its intended scope. Over-broad routing increases the chance of prompt/skill hijacking, misapplication of specialized instructions, and accidental handling of unrelated user tasks under this skill's authority.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger phrases are broad, generic, and partially natural-language templates that can match routine user requests far beyond the intended AdMapix/raw-data workflow. This creates an overbroad invocation surface where the skill may activate in unrelated contexts, causing unintended handling of user tasks and increasing the chance of misuse, confusion, or privilege overreach in agent routing.

Vague Triggers

High
Confidence
95% confidence
Finding
The manifest description uses very broad activation terms such as 'software-and-data', 'raw', 'data', and 'analysis', which can cause the skill to match many unrelated user requests. Over-broad routing increases the chance this skill is invoked outside its intended scope, leading to incorrect tool selection, user confusion, and possible interference with safer or more appropriate skills.

Vague Triggers

High
Confidence
98% confidence
Finding
The trigger keyword list contains highly generic words like 'raw', 'data', 'layer', 'apps', and 'bug fix' that are common across many unrelated tasks. This makes accidental activation likely, which can misroute user requests and degrade safety by bypassing more specialized skills with tighter scope controls.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The example trigger sentences use everyday phrasing like 'Help me' and 'I need a practical workflow' with little scope restriction, reinforcing broad matching behavior. Although the examples are not directly executable, they train activation toward ambiguous requests and increase the probability of unintended invocation.

Vague Triggers

Medium
Confidence
92% confidence
Finding
触发关键词包含非常通用的词,如“raw”“data”“layer”“apps”“revenue”“bug fix”,且示例触发句也较宽泛,容易在与本技能无关的普通软件/数据类对话中被误触发。误触发会让代理在错误上下文中调用该技能,导致输出偏题、错误执行流程,或绕过本应由更专用技能处理的安全与边界检查。

Vague Triggers

Medium
Confidence
89% confidence
Finding
技能描述将适用范围定义为只要用户提到 software-and-data、admapix、raw、data、layer,或需要‘实用流程、产物、检查清单、分析或实现支持’即可使用,边界非常宽。这会扩大技能调用面,使其在大量非目标请求中被选中,增加错误路由、结果不准确以及将本技能当作通用软件顾问使用的风险。

Vague Triggers

Medium
Confidence
93% confidence
Finding
The manifest description and default prompt are overly broad and permit implicit invocation without clear boundaries on when the skill should activate. This can cause the agent to invoke the skill in loosely related contexts, leading to unintended handling of user requests, expanded attack surface, and possible prompt-routing abuse if adversarial inputs are framed to match the vague trigger language.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger sentence uses a generic everyday phrase ('Help me ...') combined with truncated requirement text, which can cause the skill to activate in unrelated conversations. In an agent system, over-broad activation can route user data or requests into the wrong workflow, producing unsafe actions, confused delegation, or unintended handling of sensitive software/data tasks.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger specification is ambiguous and visibly truncated, so the activation boundary is unclear to both users and the routing system. This increases the chance of accidental invocation, inconsistent behavior, and misuse of the skill outside its intended context, especially because the skill targets broad software-and-data assistance.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.