Back to skill

Security audit

Software Data Github Interact Developer Helper

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a documentation-style GitHub workflow helper, but its very broad triggers and implicit auto-invocation could cause it to activate for unrelated developer requests.

Install only if you are comfortable with this skill being auto-selected for broad software, GitHub, CLI, issue, API, or bug-fix requests. Prefer explicit invocation when possible, and review any proposed repository, issue, PR, or command-line actions before allowing the agent to run or apply them.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger text is extremely broad and maps to common requests like 'help me' or 'I need a practical workflow,' which increases the chance this skill activates when a user did not intend to invoke it. In an agent ecosystem, overbroad activation can route unrelated conversations into GitHub-style workflows, causing unintended tool use, confusing outputs, or unsafe actions if the downstream skill performs repository or issue operations.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrases are broad, generic, and likely to match ordinary requests for software help, GitHub workflows, or bug fixing. This can cause the skill to activate outside its intended scope, increasing the chance of unintended execution paths, user confusion, or routing sensitive development tasks into an overly general skill.

Vague Triggers

High
Confidence
94% confidence
Finding
The manifest description uses expansive terms like 'help users with' broad categories and multiple generic task types, which can cause the skill to activate for many unrelated requests. Over-broad routing increases the chance that this skill is selected outside its intended scope, leading to confused delegation, unsafe assumptions, or interference with more appropriate specialized skills.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger list includes very broad, high-collision terms such as 'run', 'api', 'issue', and 'github', which are likely to appear in many unrelated prompts. This creates a substantial risk of accidental invocation or priority capture, allowing the skill to intercept common software requests it was not specifically designed to handle.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger section provides positive examples but no meaningful scope boundaries, exclusions, or negative examples, so the activation logic is biased toward matching rather than rejecting ambiguous requests. In a multi-skill agent environment, this can cause over-selection and unreliable routing behavior, especially given the already broad description and keyword set.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger keywords are very broad and include generic terms like github, cli, run, api, issues, and bug fix. In an agent-routing context, this can cause the skill to activate for many unrelated software conversations, leading to misrouting, unintended execution paths, or overbroad access to user tasks.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The skill description says to use the skill when a user asks for broad categories like software-and-data, github, interact, cli, or issue, but it does not define exclusions or precise activation criteria. This ambiguity increases the chance that an orchestrator or author will invoke the skill outside its intended scope, producing unsafe or irrelevant handling.

Vague Triggers

Low
Confidence
81% confidence
Finding
The example trigger phrases are phrased as very generic requests for help or practical workflows, which may teach downstream systems or users to invoke the skill on weak signals. While less severe than the keyword list itself, such examples can reinforce over-triggering and reduce routing accuracy.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The manifest description and default prompt are broad and generic, covering a wide range of software, data, GitHub, CLI, issue, checklist, analysis, and implementation requests without clear activation boundaries. In combination with agent routing, this can cause the skill to be invoked for loosely related prompts, increasing the chance of unintended tool use, over-collection of context, or execution of workflows outside the user’s actual intent.

Vague Triggers

Medium
Confidence
97% confidence
Finding
Enabling implicit invocation while the skill remains broadly described creates a routing vulnerability: the platform may auto-select this skill for many developer-adjacent prompts even when the fit is weak. That expands the attack surface for prompt confusion, unintended actions, and inappropriate exposure of repository or workflow context to a skill the user did not explicitly choose.

Vague Triggers

High
Confidence
92% confidence
Finding
The trigger sentence begins with an everyday phrase ('Help me') and then appends a long requirement description, making activation boundaries unclear. Overly broad triggers can cause the skill to activate for unrelated user requests, increasing the chance of unintended workflow execution, context hijacking, or misrouting users into this skill when another skill would be more appropriate.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The phrase 'I need a practical workflow for ...' is still too generic because many unrelated requests could match 'practical workflow' without clearly signaling GitHub interaction or repository operations. This ambiguity can lead to accidental invocation, causing the agent to expose irrelevant capabilities or follow an unintended skill path based on weak matching criteria.

Static analysis

No suspicious patterns detected.