Back to skill

Security audit

Software Data Github Interact Developer Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only developer helper skill with overly broad activation wording, but no hidden execution, persistence, credential handling, or destructive behavior was found.

This skill appears safe to install from a security standpoint, but users should be aware it may activate for broad GitHub, CLI, API, or issue-related prompts where a more specific skill might be a better fit. Review prompts before allowing any repository-changing action, as with any developer workflow helper.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger sentences are so broad and generic that they are likely to activate on ordinary developer-assistance requests, causing the skill to intercept prompts outside its intended scope. In an agent ecosystem, overbroad routing can lead to unintended instruction injection, inappropriate workflow execution, or application of this skill in contexts where safer or more specialized skills should be used.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrases are extremely broad and overlap with common user requests such as asking for help, workflows, or implementation support. In an agent ecosystem, this can cause accidental invocation of the skill in unrelated contexts, leading to over-collection of context, unintended GitHub-style actions, or confusing workflow hijacking.

Vague Triggers

High
Confidence
95% confidence
Finding
The skill description and usage guidance are broad enough to match many common software-support requests, increasing the chance the skill is invoked outside its intended niche. Over-broad routing can cause the wrong skill to handle sensitive development or security tasks, leading to poor guidance, missed safeguards, or unintended exposure of repository-related context.

Vague Triggers

High
Confidence
97% confidence
Finding
The keyword list includes highly generic terms like "run," "api," "issue," and "cli," which are common across many unrelated prompts. This makes accidental invocation likely and can hijack routing from more appropriate or safer skills, especially when users discuss operational or security-sensitive tasks using ordinary developer vocabulary.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The example trigger sentences use generic phrasing and mostly restate the broad requirement text without defining clear activation boundaries. Ambiguous examples train routing behavior toward over-matching, which can cause the skill to activate for loosely related requests and reduce reliability in handling developer or repository tasks safely.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger keywords are broad and include generic developer terms like github, cli, api, issues, and bug fix, which can cause this skill to activate for ordinary software support conversations outside its intended scope. Over-broad activation increases the chance that users are routed into an irrelevant workflow, leading to confused outputs, unintended instruction injection surface, and reduced trust in skill selection.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The top-level description defines the skill’s applicability very broadly, covering practical workflows, artifacts, checklists, analyses, and implementation support for a wide set of software-and-data and GitHub-related requests. This unclear boundary makes accidental invocation likely and can expose users to a mismatched workflow that may overreach into tasks the skill was not designed to handle safely or accurately.

Vague Triggers

Low
Confidence
80% confidence
Finding
The example trigger phrases begin with highly generic requests like 'Help me' and 'I need a practical workflow', without contrasting examples showing when the skill should not fire. These examples may train routing behavior toward over-triggering on normal assistance requests, increasing false activations and lowering reliability.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The default prompt contains broad, everyday trigger terms such as 'help me' and generic workflow language, which can cause the skill to be invoked in situations beyond the author's intended scope. Because implicit invocation is enabled, this increases the chance of accidental activation and unintended exposure of the skill's behavior in unrelated conversations.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger sentences are written in broad, natural-language phrasing that can match ordinary user requests rather than a narrowly scoped invocation pattern. In an agent environment, this increases the chance of unintended skill activation, which can cause the wrong workflow to run, expose unrelated repository context, or steer the agent into GitHub-style actions the user did not explicitly request.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger specification does not clearly separate when this skill should activate versus when a general software-help response is sufficient. That ambiguity makes the skill easier to invoke accidentally or in overlapping contexts, which can lead to incorrect tool routing and unsafe assumptions about user intent in GitHub or CLI-related tasks.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.