Back to skill

Security audit

Software Data Github Interact Developer Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only developer workflow skill with overly broad activation wording, but no hidden execution, credential use, persistence, or data exfiltration behavior was found.

Install this only if you want a broad developer-workflow helper for GitHub-style tasks. Expect that it may be invoked for some general coding, CLI, API, or issue-related requests unless the platform or user narrows activation; review generated commands or code changes before applying them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger sentences are extremely broad and partially templated, which can cause the skill to activate for vague software, GitHub, CLI, or issue-related requests that were not intended for this workflow. Over-broad activation increases the chance of inappropriate skill invocation, context confusion, and accidental execution of privileged GitHub-style actions in the wrong user context.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger phrases are broad enough to match many ordinary software-help requests, which can cause the skill to activate outside its intended scope. In an agent ecosystem, over-broad invocation increases the chance of unintended tool use, context hijacking, or the skill being selected when a narrower and safer workflow would be more appropriate.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger keywords are very broad and generic (for example, terms like 'github', 'cli', 'issue', 'run', and 'api'), which can cause the skill to activate in many unrelated contexts. This increases the chance of accidental invocation, inappropriate routing, and unintended exposure of the skill's instructions or workflows in conversations that did not actually require this skill.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The description says to use the skill when a user asks for broad categories like 'software-and-data', 'github', or 'cli', but it does not clearly define exclusion criteria or precise scope. That ambiguity can make an orchestrator invoke the skill for loosely related requests, leading to misapplication, confusing outputs, or interference with more appropriate skills.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger keywords include very broad terms such as "run", "api", "issue", and "github", which are common in many unrelated user requests. This can cause the skill to activate outside its intended scope, leading to inappropriate routing, reduced reliability, and potential interference with more suitable skills for sensitive or security-relevant tasks.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description says it should be used for broad categories like software-and-data, github, interact, cli, and issue, plus any request needing a workflow, checklist, analysis, or implementation support. That scope is overly expansive and creates ambiguous routing boundaries, increasing the chance that the skill is selected for unrelated or partially related tasks where its guidance may be incomplete or inappropriate.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill enables allow_implicit_invocation without any visible activation constraints, so the platform may trigger it for loosely related user requests. Because this skill is framed broadly around GitHub-style workflows and developer help, unintended activation could expose users to incorrect tool routing, unexpected actions, or prompt-scope overreach in contexts where the user did not explicitly request this skill.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The default prompt uses broad, generic developer-assistance phrasing that overlaps with many ordinary software requests. Combined with implicit invocation, this increases the chance the skill is selected in situations outside its intended scope, which can cause misapplication of instructions, accidental workflow interference, or user confusion about what capabilities were invoked.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger sentence is so broad and conversational that it can match many unrelated user requests, causing the skill to activate outside its intended scope. In an agent system, over-broad routing can lead to inappropriate tool selection, unintended handling of sensitive tasks, or bypass of more specialized safeguards by steering users into a generic GitHub-interaction workflow.

Vague Triggers

Medium
Confidence
91% confidence
Finding
This trigger is ambiguous and lacks enough specificity to reliably distinguish when the skill should be invoked. Ambiguous activation conditions increase the chance of accidental invocation, which can degrade reliability and may expose users to incorrect automation or misleading outputs in contexts where this skill is not appropriate.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.