Back to skill

Security audit

Software Data Admapix Raw Developer Helper

Security checks across malware telemetry and agentic risk

Overview

This skill is a documentation-only workflow helper with overly broad activation wording, but it does not request hidden access, persistence, credentials, or automatic execution.

Install only if you want an advisory workflow helper for AdMapix-style software/data tasks. Be aware that its triggers are too broad, so explicit invocation by skill name is safer than relying on automatic routing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger sentence is phrased as a broad, natural-language help request rather than a narrowly scoped invocation. This can cause unintended activation when a user casually asks for help with software, bug fixes, or AdMapix-style workflows, increasing the chance the skill runs outside the author's intended context.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The usage section defines activation examples and trigger boundaries too loosely, making it unclear when the skill should or should not be selected. In an agent ecosystem, ambiguous routing can lead to accidental invocation, misapplication of the skill to unrelated user requests, and expanded attack surface through over-broad matching.

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger phrases are extremely broad and generic (for example, 'Help me...' and 'I need a practical workflow...'), which can cause the skill to activate on many unrelated user requests. In an agent ecosystem, over-broad invocation can hijack routing, cause unintended execution, and increase the chance that this skill handles sensitive or irrelevant tasks without clear user intent.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill description and usage guidance are broad enough to match many unrelated requests, increasing the chance of unintended invocation. In agent systems, over-broad routing can expose users to the wrong workflow, produce irrelevant actions, and widen the attack surface for prompt/skill misuse.

Vague Triggers

Medium
Confidence
98% confidence
Finding
The keyword list includes highly generic terms such as 'raw', 'data', 'layer', 'apps', and 'bug fix', which are common across many unrelated conversations. This makes accidental invocation likely and allows an attacker or malformed prompt to steer the agent into using this skill outside its intended scope.

Vague Triggers

Low
Confidence
92% confidence
Finding
The example trigger sentences are truncated, vague, and do not establish clear boundaries for when the skill should or should not run. This reinforces imprecise routing behavior and can normalize activation on loosely related requests, compounding the ambiguity already present in the description and keywords.

Vague Triggers

Medium
Confidence
93% confidence
Finding
触发关键词包含非常通用的词,如“raw”“data”“layer”“apps”,会在大量与该技能无关的对话中被误匹配,导致技能被过度调用。误触发会扩大该技能对不相关任务的影响面,可能让系统输出不恰当的建议、错误路由用户请求,或在安全边界上引入上下文污染。

Vague Triggers

Medium
Confidence
90% confidence
Finding
示例触发句使用了非常宽泛的日常请求模板,如“Help me”或“I need a practical workflow”,但没有给出清晰的领域限定,容易让调度器把普通开发支持请求错误映射到该技能。这样的模糊示例会放大自动选择偏差,降低技能边界清晰度,并增加非目标场景下的不安全或低质量响应风险。

Vague Triggers

Medium
Confidence
94% confidence
Finding
The default prompt is phrased as a broad natural-language trigger ('Use $software-data-admapix-raw-developer-helper to help me ...') tied to common software-help concepts, while the skill also allows implicit invocation. That combination can cause the skill to activate in situations beyond the user's explicit intent, creating prompt-routing confusion, unintended tool use, or expansion of the skill's influence over general development and safety-related requests.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger sentence begins with a very broad phrase ('Help me ...') that can match ordinary user requests unrelated to this skill's narrow purpose. In agent routing systems, overly generic activation cues can cause accidental invocation, misrouting user requests, and unintended exposure of this skill's behavior in contexts where it was not requested.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger sentence ('I need a practical workflow for ...') is ambiguous and does not clearly delimit the technical domain, inputs, or intended use of the skill. This increases the chance of spurious activation by unrelated requests, which can lead to incorrect tool selection, confusing outputs, or policy bypass if a broader skill is invoked inappropriately.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.