Back to skill

Security audit

Software Data Admapix Raw Developer Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation/workflow helper with overly broad activation text, but it does not request privileged access, persistence, credentials, or hidden execution.

Before installing, be aware that this skill may activate for generic software or data requests because its trigger terms are broad. It is otherwise low-risk as a guidance-only skill, and users should prefer explicit invocation for AdMapix/raw-data workflow tasks.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger sentences are generic and partially templated, making accidental or overly broad activation more likely. In an agent ecosystem, unintended invocation can route unrelated user requests into this skill, causing incorrect task handling, confusion, or unsafe workflow application when the skill is used outside its intended context.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger phrases are broad, generic, and partially malformed, making them likely to match normal user requests outside the intended AdMapix-specific workflow. In an agent ecosystem, this can cause unintended skill invocation, misrouting of tasks, and expansion of the skill’s effective authority beyond what the user explicitly requested.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description is broad enough to match many unrelated requests, increasing the chance the skill is invoked outside its intended domain. Overbroad activation can route users into the wrong workflow, causing unsafe or low-quality guidance to be applied in contexts the skill was not designed to handle.

Vague Triggers

Medium
Confidence
97% confidence
Finding
The trigger keywords include generic terms such as 'raw', 'data', 'layer', 'apps', and 'bug fix', which are common across many benign conversations. This makes accidental invocation likely and expands the skill's effective authority beyond its intended scope, which can confuse downstream agents or override more appropriate specialized skills.

Vague Triggers

Low
Confidence
88% confidence
Finding
The example trigger sentences normalize catch-all activation by showing the skill being invoked for a vague and truncated requirement rather than a precise task. While less severe than the keyword list itself, these examples reinforce imprecise matching behavior and make over-triggering more likely in real deployments.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger keyword list is very broad and includes generic terms such as 'raw', 'data', 'layer', 'apps', and 'bug fix', which are likely to match many unrelated user requests. This can cause unintended skill activation, leading the agent to route tasks to this skill outside its intended scope and potentially produce irrelevant or unsafe guidance in the wrong context.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The example trigger phrases use broad natural-language patterns like 'Help me' and 'I need a practical workflow for', with only loosely scoped task text following them. Because these resemble ordinary user requests, they increase the chance of accidental invocation and ambiguous routing, especially in multi-skill environments.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The default_prompt includes very broad, natural-language trigger terms such as 'help me' alongside generic workflow language, which can cause the skill to be invoked in contexts far beyond its intended AdMapix-specific scope. Because implicit invocation is enabled, this increases the chance of unintended routing or prompt hijacking by matching ordinary user requests that were not meant for this skill.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger sentence is so broad and generic that it can match ordinary user requests unrelated to this skill, causing accidental activation. In an agent environment, over-broad routing can misapply the skill’s workflow or outputs to the wrong task, increasing the chance of unsafe automation, user confusion, or policy bypass through unintended invocation.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The activation criteria are ambiguous because they rely on vague keyword and sentence matches without clear boundaries, prerequisites, or exclusions. This makes the skill callable in contexts far outside its intended software/data support role, which can lead to incorrect execution paths, degraded trust decisions, and unnecessary exposure of any downstream capabilities the skill enables.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.