Back to skill

Security audit

Software Data Admapix Raw Developer Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow skill with overly broad activation wording, but it does not include hidden code, credential access, persistence, or destructive behavior.

Before installing, understand that this skill may be selected for broad software or data-help requests because its triggers are loose. It is reasonable to use for AdMapix-style workflow planning and maintenance, but users should prefer explicit invocation when they want this skill and avoid relying on it as a general-purpose software assistant.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger phrases are broad, natural-language sentences that overlap with ordinary user requests, which can cause the skill to activate when the user did not explicitly intend to invoke it. In an agent ecosystem, unintended invocation can route tasks to the wrong workflow, causing confusion, unsafe automation, or disclosure of user context to an unnecessary skill.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger phrases are broad enough to match many ordinary software-help requests, which can cause the skill to activate outside its intended scope. Overbroad activation increases the chance of unintended routing, user confusion, and invocation of a workflow on inputs it was not designed to handle safely or accurately.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The skill description and activation guidance use broad terms like 'software-and-data', 'raw', and generic workflow/help phrasing that can match many unrelated user requests. This can cause unintended invocation or routing, leading the agent to apply the wrong skill in contexts where its assumptions, outputs, or guidance are not appropriate.

Vague Triggers

Medium
Confidence
98% confidence
Finding
The keyword list contains vague tokens such as 'raw', 'data', 'layer', 'apps', and 'bug fix', which are common across many domains and are unsafe as standalone triggers. In a skill-routing system, such generic keywords increase the chance of accidental or overbroad activation, degrading reliability and potentially surfacing irrelevant or risky instructions in unrelated tasks.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The example trigger sentences are broad, natural-language requests that do not establish clear activation boundaries and even include truncated generic wording. This makes it easier for ordinary user requests to resemble invocation examples, encouraging false positives in tool selection and reducing operator control over when the skill is used.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger keywords are overly broad and include generic terms like "raw," "data," and "layer," which can cause the skill to activate for unrelated conversations. This creates routing ambiguity and may lead users to receive irrelevant or lower-safety workflow guidance in contexts where a more appropriate skill should handle the request.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The skill description defines activation using a very broad problem statement and a loose list of domains, without clear decision boundaries for when the skill should be selected. In practice, this can cause accidental invocation across many software/data requests, reducing predictability and increasing the chance of inappropriate guidance being applied to the wrong user task.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill enables implicit invocation while using a very broad trigger description covering generic software, data, workflow, checklist, analysis, and implementation support terms. This can cause the skill to auto-activate in contexts far beyond its intended scope, increasing the chance of unintended execution, prompt-surface expansion, or interference with other more appropriate skills.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger examples are broad, natural-language phrases that can match ordinary user requests unrelated to this specific skill. That creates an unsafe routing condition where the skill may activate outside its intended scope, causing misapplication of instructions or accidental handling of unrelated tasks.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger specification defines keywords and sample trigger sentences but does not meaningfully bound when the skill should not run. Without scope limits or exclusions, common software/data requests may invoke the skill in unintended contexts, increasing the chance of incorrect task routing and downstream unsafe or low-quality outputs.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.