Back to skill

Security audit

Software Data Admapix Raw Developer Helper

Security checks across malware telemetry and agentic risk

Overview

This skill is a documentation-style helper for AdMapix-related workflow and software/data tasks, with broad activation wording but no hidden execution, persistence, credential use, or destructive behavior.

Before installing, be aware that this skill may be selected for generic software or data requests because its triggers are broad. Users who want tighter routing should narrow activation to explicit AdMapix/raw-data workflow requests, but the inspected artifact is otherwise low-risk.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger phrases are so broad and generic that they can match ordinary user requests unrelated to this skill, causing unintended activation. In an agent ecosystem, this can route users into the wrong workflow, override more appropriate skills, and increase the chance of unsafe or irrelevant actions being taken under the skill's authority.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger phrases are broad enough to match routine requests such as generic workflow help, bug fixing, or data-related tasks, which can cause the skill to activate outside its intended scope. In an agent ecosystem, overbroad invocation increases the chance of misrouting user requests, unintended execution paths, and accidental exposure of capabilities in contexts the user did not explicitly request.

Vague Triggers

High
Confidence
94% confidence
Finding
The description activates on very broad terms like "software-and-data," "raw," and "data," which can cause the skill to be invoked for many unrelated requests. Overbroad activation increases the chance that an agent routes sensitive or off-topic tasks into this skill, leading to incorrect handling, policy bypass through misrouting, or unsafe actions being suggested outside the skill's intended scope.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger keywords include highly generic tokens such as "raw," "data," "layer," "apps," and "bug fix," which are common across many benign requests. In an automated skill-selection system, these ambiguous keywords can cause frequent false activations, making this skill a catch-all route for unrelated tasks and increasing the chance of confused-deputy behavior or inappropriate guidance in the wrong context.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example trigger sentences use generic lead-ins like "Help me" and "I need a practical workflow" plus truncated or malformed content, which makes the intended activation criteria unclear. Ambiguous examples can train downstream routing or authors to treat broad natural-language requests as valid triggers, increasing accidental invocation and unreliable skill behavior.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger list includes very generic terms such as "raw", "data", "layer", "apps", and "bug fix", which can match many unrelated user requests and cause unintended skill activation. Over-broad activation increases the chance that this skill intercepts requests outside its intended scope, potentially leading to incorrect tool use, prompt-scope confusion, or unsafe handling of unrelated tasks.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example trigger phrases are broad natural-language requests that mirror ordinary help-seeking language and do not establish clear boundaries for when the skill should or should not activate. This ambiguity can cause accidental invocation from unrelated prompts, increasing prompt-routing errors and making the skill easier to trigger unintentionally.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill enables implicit invocation while providing only a broad, loosely constrained activation description, which increases the chance the agent will auto-select this skill for ambiguous requests. Because the skill is positioned as a general helper for software/data and workflow tasks, unintended invocation could expose users to actions or guidance outside the expected scope and make policy enforcement harder.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentence is extremely broad and can match ordinary user phrasing such as asking for a 'practical workflow,' causing the skill to activate outside its intended AdMapix-style scope. Overbroad activation boundaries increase the chance of inappropriate routing, where users receive domain-specific guidance they did not request, and can be abused to steer unrelated conversations into this skill.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The invocation section lacks precise boundaries for when the skill should and should not run, and the listed keywords mix broad terms like 'raw,' 'data,' and 'apps' with a generic helper description. This ambiguity can cause accidental or adversarial invocation in unrelated contexts, increasing misrouting risk and making it easier for a user to trigger the skill with innocuous wording.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.