Back to skill

Security audit

Software Data Github Interact Developer Helper

Security checks across malware telemetry and agentic risk

Overview

This skill is a documentation-only developer workflow helper, with no executable code or hidden data access, but its activation language is overly broad.

Before installing, consider narrowing or explicitly invoking this skill only for GitHub-style issue, PR, CLI, or repository workflow help. It does not appear to run code or access private data by itself, but its broad triggers could make it appear in unrelated developer requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger sentence begins with a very generic help-request pattern ('Help me ...'), which can cause the skill to activate when users are making ordinary requests rather than explicitly intending to invoke this specific skill. In an agent ecosystem, overly broad activation increases the chance of unintended execution paths, irrelevant tool use, or privilege-bearing workflows being invoked without clear user intent.

Vague Triggers

Medium
Confidence
81% confidence
Finding
This trigger uses a broad 'I need a practical workflow for ...' pattern without clear constraints on task type, repository scope, or GitHub-specific intent. Such ambiguous activation language can over-match normal conversation and route users into this skill when another skill or no skill at all would be more appropriate, creating reliability and safety issues in downstream automated actions.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are broad, natural-language prompts that could cause the skill to activate for loosely related requests rather than explicit user intent. In an agent ecosystem, overbroad activation increases the chance of unintended execution paths, context confusion, and unsafe delegation into GitHub-style workflows that may touch code, issues, or automation without sufficient user confirmation.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger keyword list is extremely broad and includes generic terms like "run," "api," "issue," and "github," which can cause this skill to activate in many unrelated contexts. Over-broad activation increases the chance that the wrong skill handles user requests, leading to confusion, unsafe guidance in mismatched scenarios, or accidental disclosure of context to an unnecessary skill path.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The description says to use the skill whenever a user asks for broad categories like software-and-data, github, interact, cli, issue, or any practical workflow or analysis support, which effectively makes the activation boundary very loose. This can cause unintended invocation outside the intended GitHub-style developer-helper use case, degrading routing reliability and potentially surfacing irrelevant or risky instructions in the wrong context.

Vague Triggers

Low
Confidence
84% confidence
Finding
The trigger examples are truncated, vague, and unrealistic, so they do not give reliable boundaries for when the skill should or should not activate. Poor examples can reinforce over-triggering behavior and make routing errors more likely, though the impact is lower than explicit broad keywords because examples are guidance rather than the main matching mechanism.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger list includes very common terms such as "run", "api", "issue", and "github", which can cause the skill to activate in many unrelated conversations. Over-broad activation increases the chance that this skill intercepts requests outside its intended scope, leading to misrouting, confusing behavior, or unsafe guidance being applied in the wrong context.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The description defines a very broad set of use cases, covering software, data, GitHub, CLI, issues, workflows, analysis, and implementation support. This ambiguity can cause unintended invocation or over-delegation to the skill when a narrower, more specialized skill would be safer and more appropriate.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The default prompt contains a very broad activation phrase tied to common concepts like software, data, GitHub, bugs, safety, reliability, and implementation help. This creates a realistic risk of unintended routing or invocation during ordinary user requests, causing the agent to engage outside of clearly intended contexts and potentially expose users to unexpected tool behavior or prompt influence.

Vague Triggers

Medium
Confidence
95% confidence
Finding
Enabling implicit invocation without strict activation constraints allows the platform to auto-select this skill based on vague semantic similarity rather than clear user intent. In a broadly described developer-assistance skill, that increases the chance of accidental invocation across many unrelated conversations, which can lead to overreach, unintended actions, or prompt-surface expansion.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger sentence is excessively broad and can match ordinary user requests, causing the skill to activate in contexts where it was not specifically intended. Over-broad activation increases the chance of inappropriate tool use, confusing workflow injection, or routing sensitive development requests into a skill whose behavior may not be the best fit.

Vague Triggers

Medium
Confidence
91% confidence
Finding
This trigger remains underspecified and can fire on a wide range of normal requests because it does not clearly distinguish this skill from many other software-help workflows. In practice, such ambiguity can lead to unintended invocation, misrouting, and overexposure of the skill in conversations involving code, issues, or operational tasks.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.