Back to skill

Security audit

Software Data Admapix Raw Developer Helper

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-style helper skill with overly broad activation wording, but no evidence of hidden execution, data access, persistence, credential handling, or destructive behavior.

Safe to install for AdMapix-style workflow help, but expect possible over-activation because its trigger phrases are broad. Invoke it explicitly by name for relevant tasks, and avoid relying on implicit routing for generic software or data questions.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger phrase is so broad and awkwardly templated that it can match generic user requests unrelated to the intended AdMapix/raw-data workflow. In an agentic system, this raises the chance of unintended skill activation, causing the wrong workflow or instructions to be injected into ordinary conversations and potentially steering behavior outside user intent.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The activation guidance does not define precise scope boundaries, so agents may be unable to reliably distinguish when this skill should or should not run. Ambiguous routing logic increases the risk of over-activation, user confusion, and accidental application of this skill's instructions in unrelated contexts.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrases are broad enough to match ordinary help requests such as asking for a practical workflow or implementation support, which can cause the skill to activate outside its intended scope. In an agent ecosystem, over-broad routing can hijack unrelated tasks, leading users to receive unintended instructions, data handling paths, or tool behavior they did not explicitly request.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description and use conditions are broad enough to match many ordinary software or data-help requests, which can cause the skill to be invoked outside its intended AdMapix-specific scope. Overbroad routing increases the chance that users receive mismatched instructions or that this skill supersedes safer, more specialized skills with narrower guardrails.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The keyword list includes highly generic terms such as 'raw', 'data', 'layer', 'apps', and 'bug fix', which are common across many unrelated requests. This makes accidental or excessive invocation likely, expanding the skill's operational scope and weakening routing precision, which is a security and reliability concern in agentic systems.

Vague Triggers

Low
Confidence
88% confidence
Finding
The example trigger phrases are generic and truncated, and they do not demonstrate clear invocation boundaries or safe scoping. Poor examples encourage ambiguous matching behavior and make it harder for maintainers or routing systems to distinguish legitimate use from unrelated requests.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger keywords are overly broad and include generic terms like 'raw', 'data', 'layer', and 'apps', which can cause the skill to activate for many unrelated requests. Over-broad activation increases the chance that the wrong skill handles user input, leading to confused behavior, unsafe delegation, or accidental application of this workflow in contexts it was not designed for.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The activation description covers a very wide range of requests, including general implementation support, analysis, checklists, and workflows around several broad technical themes. This ambiguity can cause unintended invocation outside the intended AdMapix-style domain, increasing the risk of misrouting user tasks and producing irrelevant or unsafe outputs under the wrong skill assumptions.

Vague Triggers

Low
Confidence
88% confidence
Finding
The example trigger phrases are generic and effectively restate the broad demand claim rather than demonstrating constrained activation conditions. Poorly constrained examples can encourage loose matching behavior and make it easier for unrelated requests to be interpreted as eligible for this skill.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The default prompt uses the generic phrase 'help me' as invocation wording, which is overly broad and can cause the skill to be triggered in many unrelated user requests. Because implicit invocation is enabled, this increases the chance of accidental routing into this skill, exposing users to unintended behavior and making prompt-selection controls less reliable.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger phrases are broad, generic, and partially composed of normal conversational language, which can cause the skill to activate for unrelated software/help requests. In an agent ecosystem, overbroad activation can route users into the wrong workflow, creating prompt-scope confusion and increasing the chance that sensitive context or actions are handled by an unintended skill.

Static analysis

No suspicious patterns detected.