Back to skill

Security audit

Software Data Github Interact Developer Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-style developer helper with overly broad activation wording, but it does not install code, request secrets, persist data, or perform hidden actions.

Before installing, understand that this helper may be invoked for general GitHub or developer-support requests because its triggers are broad. It appears safe from a security perspective, but users may prefer narrower activation wording to reduce accidental use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentence is so broad and generic that it can cause the skill to activate in contexts where the user did not explicitly intend to invoke it. In an agent environment, unintended invocation can route user requests into the wrong workflow, causing confusing actions, incorrect task handling, or accidental execution of GitHub-related behaviors.

Vague Triggers

Medium
Confidence
91% confidence
Finding
An ambiguous trigger that does not clearly define when the skill should activate increases the chance of misrouting user requests. Because this skill is positioned for practical software, issue, CLI, and GitHub-style assistance, accidental activation could lead an agent to prioritize this skill over a more appropriate one and produce unintended guidance or actions.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrases are generic and overlap heavily with normal software-support requests such as help with GitHub, issues, CLI, APIs, bug fixes, and workflows. In an agent-routing system, this can cause the skill to activate unintentionally, intercept requests outside its intended scope, and influence handling of sensitive repository or operational tasks without clear user intent.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill description is broad enough to match many ordinary developer requests such as GitHub help, CLI usage, issues, APIs, and implementation support. This can cause unintended invocation or routing collisions, making the agent apply this skill in contexts where a more specific or safer skill should be used, reducing predictability and potentially exposing users to irrelevant or overly powerful workflow guidance.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The keyword list includes highly generic terms like 'github', 'cli', 'issue', 'run', and 'api', which are common across normal developer conversations. Generic triggers increase the chance of accidental activation and skill overlap, which can degrade security by causing unintended tool selection or unreviewed automation in unrelated contexts.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The example trigger phrases are written in broad, natural language that lacks clear operational boundaries, so they can match routine user requests far beyond the intended niche. This reinforces over-triggering behavior and makes activation logic ambiguous, increasing the likelihood of incorrect skill dispatch and user confusion.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger keywords are broad and overlap with common software-development conversations such as 'github', 'cli', 'api', 'run', and 'issue'. This can cause the skill to activate in unrelated contexts, leading the agent to inject this workflow when the user did not intend it, which increases the chance of misrouting, irrelevant actions, or unsafe overreach into general development tasks.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The example trigger phrases use generic help-seeking language like 'Help me' and 'I need a practical workflow', which does not clearly distinguish this skill from many other assistant tasks. In a routing system, such examples can bias selection toward this skill for ordinary requests, causing unintended invocation and potentially broad, unnecessary handling of developer workflows.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill enables allow_implicit_invocation without any visible activation constraints, which can cause the agent to invoke this skill on loosely related user requests. Because the skill is framed around broad GitHub-style development help, ambiguous triggering can expand the skill's reach beyond clearly intended contexts and increase the chance of inappropriate tool use or unexpected workflow execution.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The default prompt uses very broad, generic wording like helping with GitHub-style workflows, bug fixing, hardening, reliability, and implementation support. This overlaps with many common developer requests, making accidental or overbroad activation more likely, especially when combined with implicit invocation.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrases are extremely broad and include common language such as 'Help me' and 'I need a practical workflow', which can cause the skill to activate for many unrelated requests. In an agent environment, this can lead to unintended routing, context hijacking, or the skill being invoked when a narrower, safer, or more appropriate skill should handle the request.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.