Back to skill

Security audit

Software Data Github Interact Developer Helper

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-style developer workflow skill with broad activation wording, but no code, credential use, persistence, or hidden actions were found.

Before installing, be aware that this skill may activate for general software or GitHub-related requests because its trigger wording is broad. It appears safe as a workflow helper, but users who want precise routing should prefer explicit invocation or narrow its triggers.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (13)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger sentence starts with broad everyday language ('Help me') and then embeds a long, generic requirement description, making accidental activation more likely. In an agent ecosystem, overly broad triggers can cause the wrong skill to be invoked for unrelated requests, leading to unintended actions, confusing outputs, or unsafe workflow execution in contexts involving GitHub, CLI, issues, or APIs.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The phrase 'I need a practical workflow for...' is generic and lacks clear activation boundaries, so it may match many unrelated user requests. Because this skill is positioned for practical GitHub-style workflows and adjacent implementation support, ambiguous triggering increases the chance of misrouting prompts into a skill that may generate operational guidance or artifacts outside the user's actual intent.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrases are broad enough to match many ordinary software-help requests, which can cause the skill to activate outside its intended scope. In an agent environment, overbroad activation increases the chance of the wrong workflow being invoked, potentially leading to inappropriate actions, misleading outputs, or unsafe handling of GitHub- or CLI-related tasks.

Vague Triggers

High
Confidence
95% confidence
Finding
The manifest description is extremely broad and includes generic terms like 'software-and-data', 'github', and 'practical workflow' that could match many unrelated user requests. This can cause inappropriate skill activation, leading the agent to apply this skill outside its intended scope and potentially override more relevant or safer specialized behavior.

Vague Triggers

High
Confidence
98% confidence
Finding
The trigger keyword list uses vague, high-frequency terms such as 'run', 'api', 'issue', and 'github' without qualifiers. These terms are likely to collide with many normal conversations, causing this skill to activate unexpectedly and increasing the chance of misrouting user requests or interfering with more appropriate skills.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example trigger phrases are open-ended and closely resemble everyday requests for help, which reinforces overly permissive activation behavior. Because they do not require specific GitHub workflow context, they make accidental invocation more likely and weaken routing precision.

Vague Triggers

Medium
Confidence
95% confidence
Finding
触发关键词包含 `run`、`api`、`github`、`issue` 等高度通用词,容易在大量无关上下文中误触发该技能。误触发会让代理在错误场景中调用该技能,导致任务路由偏移、输出不相关建议,甚至在涉及代码/CLI/仓库操作时放大错误操作风险。

Vague Triggers

Medium
Confidence
92% confidence
Finding
技能描述中的适用范围覆盖 `software-and-data, github, interact, cli, issue` 及“实用流程、产物、检查清单、分析或实现支持”等宽泛需求,边界非常模糊。这样的描述会让编排器或调用方难以区分它与其他通用开发类技能的职责,增加误选和权限/操作链路错配的机会。

Vague Triggers

Low
Confidence
86% confidence
Finding
示例触发句几乎只是重复需求文案,表述笼统,且没有给出不应触发的反例或排除条件。这会让用户和上层代理对触发语义形成过宽预期,进一步增加错误调用和与相邻技能冲突的概率。

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill enables implicit invocation but does not define a narrowly scoped trigger, which can cause the agent to activate in response to loosely related requests. Because this skill targets broad 'github-style workflows' and practical developer help, unintended activation could expose users to prompt injection surface, workflow confusion, or execution of actions under the wrong skill context.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The default prompt contains a very broad trigger phrase covering common developer terms like software, data, github, interact, cli, issue, workflow, analysis, and implementation support. This overlaps with routine conversation and makes accidental or adversarial invocation much more likely, especially in environments where prompt routing is automatic.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger sentences are highly generic and can match ordinary user phrasing unrelated to this specific skill, which creates a prompt/skill-routing overreach risk. In an agent ecosystem, broad activation can cause the wrong skill to be invoked, leading to unintended actions, confusing outputs, or unsafe workflow guidance in contexts the skill was not meant to handle.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The usage signals define broad keywords like 'run', 'api', 'issue', and 'cli' without sufficient scope boundaries, making accidental or inappropriate invocation likely. Because this skill is framed as a general developer helper, weak trigger constraints increase the chance it intercepts unrelated software requests and influences downstream agent behavior outside its intended requirement.

Static analysis

No suspicious patterns detected.