Back to skill

Security audit

Software Data Github Interact Developer Helper

Security checks across malware telemetry and agentic risk

Overview

This is a non-executable developer workflow skill with overly broad activation wording, but no hidden install steps, persistence, credential use, or automatic high-impact actions.

Before installing, expect this skill to be a broad developer-workflow helper that may activate on generic GitHub, CLI, issue, API, or bug-fix requests. Users who want precise routing should narrow the trigger wording or disable implicit invocation, but the inspected artifact does not show malicious behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger phrases are extremely broad and partially duplicated from the requirement text, which makes accidental or unintended activation more likely. In an agent-skill ecosystem, ambiguous activation boundaries can cause the wrong skill to engage on unrelated prompts, increasing the chance of unsafe actions, confused delegation, or disclosure of context to a workflow the user did not intend to invoke.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrases are broad, generic, and phrased in ways that can match ordinary user requests unrelated to this specific skill. That increases the chance of accidental invocation or routing collisions, causing the wrong skill to handle user input and potentially exposing repository, issue, or workflow actions in unintended contexts.

Vague Triggers

High
Confidence
97% confidence
Finding
The skill description is scoped so broadly that it can activate for many ordinary software/help requests, including generic GitHub, CLI, API, bug-fix, and workflow asks. Over-broad routing increases the chance the wrong skill is invoked, which can bypass more appropriate specialized or safer skills and cause unintended data handling or unsafe operational guidance.

Vague Triggers

High
Confidence
98% confidence
Finding
The keyword trigger list contains highly generic terms such as 'github', 'cli', 'issue', 'run', and 'api', which are common across a wide range of unrelated requests. This makes accidental activation likely and can let this skill preempt safer or more relevant skills, leading to poor task routing and increased exposure to unsafe instructions or unnecessary repository interactions.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The example trigger phrases are written in broad everyday language and effectively teach the router to match on vague requests without clear boundaries. These examples reinforce over-activation behavior, making it easier for ordinary user prompts to invoke the skill even when the user's need is only loosely related.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger keywords include very broad terms such as `run`, `api`, `issues`, and `github`, which are common in many unrelated user requests. This can cause the skill to activate unintentionally and inject workflow guidance into contexts where it was not requested, increasing the risk of misrouting, policy bypass through over-broad matching, or confusing users with irrelevant actions.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill description defines its usage scope extremely broadly, covering practical workflows, artifacts, checklists, analysis, and implementation support for a wide set of software/GitHub-related needs. Such vague activation conditions make the router more likely to select this skill for loosely related requests, which can create unsafe overreach, unexpected behavior, or accidental handling of tasks better suited to narrower skills.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill enables implicit invocation while providing only a very broad, generic description of when it should activate. This increases the chance the agent is auto-selected for loosely related requests, which can cause unintended tool use, prompt-context expansion, or routing into a skill with capabilities the user did not explicitly request.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The default prompt uses broad, everyday language such as helping with practical workflow, checklist, analysis, or implementation support, which can overlap with many common developer requests. In combination with implicit invocation, this broad phrasing can cause overmatching and accidental activation, exposing users to unintended behavior or causing the agent to act outside the expected scope.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger sentence is so broad and generic that it can match ordinary user language unrelated to this specific skill, causing unintended activation. In an agent-routing context, overbroad triggers can misroute requests, expose the skill in contexts it was not designed for, and increase the chance that downstream GitHub-style actions or advice are invoked without sufficient user intent.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The invocation guidance defines trigger scope too loosely and includes natural-language prompts that are effectively catch-all phrases. This makes the skill easier to activate accidentally or through prompt shaping, which can distort tool selection and cause the agent to apply this workflow where a safer or more relevant skill should have been chosen.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.