Back to skill

Security audit

Software Data Github Interact Developer Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only helper skill with broad routing language but no hidden execution, credential use, persistence, or destructive behavior.

Installers should know this skill may activate for broad GitHub, CLI, API, issue, or bug-fix requests. It is best used when the user explicitly wants repository or developer-workflow help; maintainers should narrow the triggers and localize the Chinese examples.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger examples are broad, generic, and partially duplicated from the requirement text rather than being tightly scoped to clear user intent. This raises the chance of unintended invocation in unrelated conversations, which can cause the agent to apply the wrong workflow, expose repository-related actions in the wrong context, or increase the chance of unsafe automation around GitHub-style tasks.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger phrases are broad, generic, and partially match common user requests such as asking for help, workflows, or implementation support. This can cause unintended auto-invocation or routing collisions, leading the wrong skill to activate and potentially exposing users to actions or guidance outside their intent. In a GitHub/workflow-oriented skill, accidental activation is more dangerous because it may steer issue, PR, CLI, or repo-related operations without sufficiently precise user intent.

Natural-Language Policy Violations

Medium
Confidence
81% confidence
Finding
The Chinese README presents mixed-language user guidance while the trigger examples remain English-only, which can confuse users about how to invoke the skill correctly. This is not a direct code-execution flaw, but it can increase mis-invocation, user misunderstanding, and reliance on ambiguous broad triggers, indirectly compounding routing and safety issues. In this context, the impact is limited but relevant because precise invocation matters for tools that support GitHub-style operational workflows.

Vague Triggers

High
Confidence
95% confidence
Finding
The skill description and usage guidance are broad enough to match many routine software, GitHub, or CLI requests, which can cause the skill to activate outside its intended scope. Over-broad activation increases the chance that irrelevant or less-safe instructions are injected into unrelated tasks, reducing routing precision and potentially bypassing more appropriate specialized skills.

Vague Triggers

High
Confidence
98% confidence
Finding
The keyword list contains highly generic terms such as 'run', 'api', 'issues', and 'bug fix' without qualifiers, making accidental invocation very likely across unrelated conversations. In agent ecosystems, vague triggers can hijack routing, cause skill overreach, and expose users to inappropriate workflow guidance in contexts the skill was not designed to handle.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example trigger sentences are written as broad everyday requests and encourage activation from incomplete or ambiguous prompts. This normalizes imprecise routing behavior and can make the skill fire on partial matches, increasing confusion and the risk of irrelevant or conflicting assistance.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger list includes very broad generic terms such as 'run', 'api', 'issue', and 'github', which can match many unrelated user requests and cause the skill to activate unintentionally. Over-broad activation increases the chance that this skill intercepts tasks outside its intended scope, leading to incorrect guidance, workflow confusion, or unsafe actions being suggested in the wrong context.

Vague Triggers

High
Confidence
94% confidence
Finding
The skill description says it should be used when a user asks for broad categories like software-and-data, github, interact, cli, or issue, which leaves the activation boundary unclear. This ambiguity can cause accidental invocation for loosely related requests, reducing predictability and potentially routing sensitive or unrelated tasks into an ill-fitting workflow.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The default prompt contains a very broad activation phrase and generic task wording, which can cause the skill to be invoked in ordinary conversation rather than only when explicitly relevant. In a GitHub/developer-helper context, unintended invocation could expose users to unnecessary prompt steering, accidental workflow execution, or inappropriate trust in the skill for unrelated requests.

Vague Triggers

High
Confidence
91% confidence
Finding
The trigger sentence is overly broad and can match ordinary user phrasing, causing the skill to activate in contexts where it was not specifically intended. In an agent ecosystem, unintended invocation can route user requests into the wrong workflow, increasing the chance of inappropriate actions, misleading outputs, or accidental execution of Github-adjacent guidance on unrelated tasks.

Vague Triggers

Medium
Confidence
87% confidence
Finding
This trigger uses a vague request pattern that does not clearly distinguish this skill from many other software-help requests. Because the skill is framed broadly around practical workflows, a vague activation phrase can cause over-selection, resulting in confused routing, reduced reliability, and possible exposure of users to irrelevant or risky instructions in the wrong context.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.