Back to skill

Security audit

Software Data Github Interact Developer Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only developer workflow helper with overbroad activation wording, but no hidden execution, credential access, persistence, or destructive behavior.

Before installing, be aware that this skill may be selected for general GitHub, CLI, issue, API, or bug-fix requests because its triggers are broad. It appears safe as a guidance-only skill, but users who want precise routing should narrow the triggers or disable implicit invocation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger sentences are generic and expansive enough that the skill may activate for loosely related requests involving software, GitHub, APIs, issues, or bug fixes. This can cause unintended invocation of the skill in contexts the user did not explicitly request, increasing the chance of overreach, misleading workflow execution, or unauthorized handling of development-related tasks.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrases are broad, generic, and partially templated around common help requests, which increases the chance this skill activates for ordinary unrelated GitHub or software-support prompts. In an agent-routing context, this can cause unintended invocation, context hijacking, or execution of the wrong workflow, especially because the skill is positioned to handle issues, PRs, CLI, and API tasks.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger keyword list includes very common terms such as "cli," "issue," "run," and "api," which are likely to appear in many unrelated requests. This can cause unintended skill invocation, leading the agent to apply this skill outside its intended scope and potentially produce irrelevant, risky, or overly privileged GitHub-style workflow guidance in the wrong context.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The example trigger phrases are broad, repetitive, and phrased in everyday language rather than using distinct activation patterns. Because they mirror generic help requests, they reinforce overbroad routing behavior and increase the chance that unrelated user prompts will invoke this skill unnecessarily.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger keywords are broad and include generic terms like github, cli, issue, run, and api, which can appear in many unrelated user requests. This can cause the skill to activate unintentionally, leading to incorrect routing, overbroad data handling, or the model applying this skill in contexts where a narrower and safer workflow should have been used.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example trigger phrases are vague and closely resemble ordinary help requests, so they do not clearly distinguish when this skill should be invoked versus a general coding or workflow assistant. In practice, this increases the chance of accidental activation and prompt-routing errors, especially because the examples embed broad demand language instead of precise task boundaries.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill enables allow_implicit_invocation without any narrow activation criteria, so the agent may invoke this skill on loosely related requests. Because the skill is framed broadly around GitHub-style workflows and developer help, ambiguous auto-selection can cause unintended execution, context leakage into the skill, or overbroad tool use when the user did not explicitly request it.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The default prompt is written in broad natural language covering bug fixes, hardening, reliability, adjacent skills, and general workflow support, which overlaps with many ordinary developer requests. In combination with implicit invocation, this increases the chance the skill is selected for unrelated tasks, potentially exposing user context or causing the agent to take actions under an inappropriately scoped capability.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrases are extremely broad and include common verbs like 'help me' and 'I need a practical workflow', which can cause the skill to activate for many unrelated requests. In an agent-routing system, this can misroute benign user prompts into a powerful GitHub-oriented workflow, increasing the chance of unintended tool use, confusing outputs, or unsafe task expansion.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.