Back to skill

Security audit

Software Data Admapix Raw Developer Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overly broad activation wording but no hidden execution, credential use, persistence, or data exfiltration behavior.

Installers should understand that this skill may activate for generic software/data phrasing unless routing is tightened. Prefer explicit AdMapix/raw-data prompts when using it, and consider narrowing the keywords and examples before publishing broadly.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are generic and broad enough to match ordinary software-help requests, which can cause the skill to activate outside its intended scope. In an agent ecosystem, this can misroute user tasks, override more appropriate skills, and increase the chance that unrelated requests are handled with assumptions or workflows not meant for them.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are broad enough to match ordinary requests for software, data, bug fixing, or practical workflows, which can cause the skill to activate outside its intended niche. Overbroad invocation increases the chance of misrouting user tasks, unexpected handling of unrelated prompts, and accidental exposure of users to a workflow they did not intend to invoke.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill description is broad enough to match many ordinary software-help requests, which can cause unintended activation and routing to this skill outside its intended scope. In agent systems, overbroad dispatch increases the chance that users receive irrelevant or lower-safety guidance, and can overshadow more specialized skills.

Vague Triggers

Medium
Confidence
97% confidence
Finding
The keyword list includes highly generic terms such as 'raw', 'data', 'layer', 'apps', and 'bug fix', which are common across countless benign requests. This makes false activations likely, reducing routing integrity and potentially exposing users to mismatched instructions or unintended skill behavior.

Vague Triggers

Low
Confidence
89% confidence
Finding
The example triggers use everyday phrasing and truncated generic language that does not clearly constrain when the skill should activate. This can train maintainers or routing logic toward permissive matching, further increasing accidental invocation rates.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger keyword list includes very broad generic terms such as "raw", "data", "layer", "apps", and "bug fix", which can match many unrelated user requests and cause unintended skill activation. Over-broad activation increases the chance that the skill intercepts conversations outside its intended scope, potentially leading to confused delegation, irrelevant outputs, or accidental processing of sensitive project context.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The example trigger phrases are ambiguous and written in broad, everyday wording, so they do not establish clear boundaries for when the skill should be invoked. This makes accidental or overly eager activation more likely, especially because the examples contain generic requests like "Help me" and "I need a practical workflow," which could apply to many unrelated tasks.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The default prompt embeds a long, generic activation phrase about broad user needs rather than a narrowly scoped trigger, which increases the chance of unintended invocation from ordinary user language. Because implicit invocation is enabled, this can cause the skill to activate in contexts where the user did not explicitly intend it, expanding its influence over prompts and potentially causing unsafe or irrelevant behavior.

Vague Triggers

High
Confidence
92% confidence
Finding
The trigger sentence begins with a very broad everyday phrase ('Help me ...'), which can cause the skill to activate during ordinary user requests that are not actually asking for this specific AdMapix-related capability. Unintended invocation can route unrelated conversations through the wrong skill, increasing the chance of inappropriate data handling, misleading outputs, or bypass of more suitable safeguards in other skills.

Vague Triggers

Medium
Confidence
88% confidence
Finding
This trigger uses broad activation wording ('I need a practical workflow for ...') that lacks enough specificity to distinguish the skill's intended use from many ordinary software-support requests. In an agent environment, overly permissive triggers can cause accidental invocation and misapplication of this skill to unrelated tasks, reducing reliability and potentially exposing user context to an unnecessary workflow.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.