Back to skill

Security audit

Software Data Github Interact Developer Helper

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only GitHub/developer workflow helper with overly broad activation wording but no executable code, credential access, persistence, or hidden data flow.

Before installing, understand that this skill may be invoked for broad GitHub or developer-help prompts because implicit invocation is enabled and the trigger terms are generic. It appears safe from an execution and data-access perspective, but a maintainer should narrow the triggers if precise routing matters.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases are extremely broad and can match many ordinary software-help requests, causing the skill to activate outside its intended scope. In an agent environment, overbroad routing can steer users into an unintended workflow, increasing the chance of incorrect actions, unsafe automation, or prompt-surface expansion from irrelevant contexts.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are extremely broad and include common terms like "github", "issue", "api", and generic request forms such as "Help me" or "I need a practical workflow," which can cause the skill to activate on ordinary, unrelated user requests. This increases unintended invocation risk, making it easier for the skill to intercept tasks outside its intended scope and potentially override more appropriate or safer skills.

Vague Triggers

High
Confidence
95% confidence
Finding
The skill description is extremely broad and matches common developer-assistance requests such as software, GitHub, CLI, issues, workflows, and implementation support. In agent-routing systems, this can cause the skill to activate for many unrelated prompts, creating prompt-scope hijacking risk where a generic skill intercepts requests better handled by safer or more specific skills.

Vague Triggers

High
Confidence
98% confidence
Finding
The trigger keywords include highly generic terms like 'github', 'cli', 'issue', 'run', and 'api', which are likely to appear in a wide range of unrelated user requests. This makes accidental or strategic over-invocation easy, allowing the skill to dominate routing and potentially expose users to irrelevant instructions or bypass more specialized guardrailed skills.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The example trigger sentences use everyday phrasing like 'Help me' and 'I need a practical workflow', which teaches the router that ordinary user language should map to this skill. That broadens activation beyond the intended niche and increases the chance of prompt-capture behavior in multi-skill environments.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger keywords are very broad and overlap with common developer conversations such as github, cli, api, issue, and run. This can cause the skill to activate in unrelated contexts, leading to unintended instruction injection into normal workflows and increasing the chance that users receive irrelevant or unsafe guidance without explicitly requesting this skill.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The example trigger phrases are phrased as everyday help requests and do not establish clear boundaries for when this skill should or should not activate. In systems that route by similarity or example matching, this broad wording can over-match many ordinary support requests and steer users into an unintended workflow.

Natural-Language Policy Violations

High
Confidence
85% confidence
Finding
The skill content is entirely in Chinese and does not provide user choice, fallback behavior, or justification for the locale restriction. This can cause users or downstream agents to misunderstand instructions, validation steps, or safety constraints, which is especially risky for a developer-helper skill expected to influence implementation and operational decisions.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The default prompt and short description are highly generic and broad, encouraging invocation for a wide range of vaguely related software, GitHub, CLI, issue, checklist, and implementation tasks. This increases the chance of accidental or implicit activation in contexts the skill was not carefully scoped for, which can expose users to unintended actions, unsafe advice, or overbroad task handling.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger phrases are highly generic ('Help me...', 'I need a practical workflow...') and can match ordinary user requests that were not intended to invoke this specific skill. In an agent-routing environment, overly broad triggers can cause accidental activation, leading the agent to apply GitHub-oriented workflows to unrelated tasks, which increases the risk of confused-deputy behavior and unintended actions.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.