Back to skill

Security audit

Software Data Admapix Raw Developer Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only helper skill with overly broad activation wording but no hidden execution, persistence, credential access, or destructive behavior.

Before installing, be aware that this skill may be selected for generic software or data requests because its triggers are broad. It appears safe as a helper, but users should invoke it explicitly for AdMapix-style workflow support and avoid relying on implicit routing for unrelated tasks.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger examples are broad, natural-language phrases that can match ordinary user requests without clear scoping or consent, increasing the chance this skill activates in contexts the user did not explicitly intend. In an agent ecosystem, over-broad activation can route unrelated requests into this workflow, causing mis-execution, confusion, or unsafe handling of tasks outside the skill’s intended domain.

Vague Triggers

High
Confidence
90% confidence
Finding
The trigger phrases are broad enough to match common user requests such as generic help with workflows, data, apps, rankings, revenue, or bug fixes. This can cause unintended skill activation, expanding the skill's reach beyond its intended scope and increasing the chance that unrelated requests are handled by the wrong skill, which is a prompt-routing and safety-boundary problem.

Vague Triggers

High
Confidence
95% confidence
Finding
The skill description and usage guidance are broad enough to activate on generic software/data requests rather than a narrowly scoped AdMapix-specific task. Over-broad routing can cause the wrong skill to engage, leading to unintended data handling, misleading outputs, or bypass of safer/specialized skills in mixed-agent environments.

Vague Triggers

High
Confidence
98% confidence
Finding
The keyword list includes ambiguous single words like 'raw', 'data', 'layer', 'apps', and 'revenue', which are common across many unrelated requests. In an automated skill-selection system, these terms can cause frequent false activations and route sensitive or unrelated work into this skill's workflow unexpectedly.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The example trigger sentences use everyday phrasing and effectively suggest invocation for a wide class of generic help requests. Because examples often seed downstream matching or author behavior, unclear activation boundaries increase the chance of accidental invocation and poor task routing.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger keywords are very broad and include common terms like 'raw', 'data', and 'layer', which can overlap with ordinary conversations and unrelated tasks. This creates a real risk of accidental skill activation, causing the agent to follow this skill's workflow when it was not the user's intent and potentially overriding more appropriate routing or safety context.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The example trigger phrases use generic activation language such as 'Help me' and 'I need a practical workflow', which does not clearly distinguish when this specific skill should be invoked. If the platform uses examples to shape routing behavior, these patterns can broaden activation beyond the intended scope and lead to misrouting, confusing outputs, or unintended execution of this skill in unrelated contexts.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill enables implicit invocation, but the trigger description is broad and vague, covering generic software/data help and multiple adjacent tasks. This can cause the agent to auto-select the skill in situations the user did not clearly intend, increasing the risk of over-broad activation, unintended data exposure to the skill context, or execution of unsafe workflows under an irrelevant skill.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger sentence is extremely broad and can match ordinary user phrasing, causing the skill to activate outside its intended scope. Over-broad activation can route unrelated requests into this skill, creating confused-deputy behavior, poor safety boundary selection, and increased chance of the agent producing inappropriate workflow or implementation guidance for the wrong task.

Vague Triggers

Medium
Confidence
93% confidence
Finding
This trigger is ambiguous and broadly phrased, so normal requests for a 'practical workflow' may incorrectly invoke the skill even when the user is asking about unrelated software or data tasks. In an agent environment, that can misroute execution, expose irrelevant capabilities, and degrade trust and safety by selecting a skill on weak semantic evidence.

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.