Back to skill

Security audit

Software Data Self Improving Developer Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-style developer workflow skill with broad activation wording but no executable code, persistence, credential handling, or hidden data movement.

This skill appears safe to install as a workflow helper. Be aware that its broad trigger words and implicit invocation may make it appear during ordinary software-help requests; users who want tighter control should invoke it explicitly or narrow its activation metadata.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger sentences are generic enough to match many ordinary software-help requests, which can cause this skill to activate outside its intended scope. Over-broad activation increases the chance of unintended instruction injection into unrelated workflows, confusing routing, and unexpected handling of user requests by a skill that positions itself as a self-improving developer helper.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrases are broad enough to match ordinary help requests such as bug fixing or practical workflow assistance, which can cause the skill to activate outside its intended scope. In an agent environment, overbroad activation can route unrelated user requests into a self-improving workflow, increasing the chance of unintended actions, prompt hijacking, or misuse of elevated tool access.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger list includes very generic terms like 'self', 'improving', 'captures', 'enable', and 'bug fix', which are likely to appear in many unrelated user requests. This can cause the skill to activate unintentionally, leading to prompt-routing errors, irrelevant instructions being injected into conversations, and reduced reliability of the agent system.

Vague Triggers

High
Confidence
94% confidence
Finding
The invocation guidance says to use the skill when a user asks for broad concepts like 'software-and-data', 'self', or 'improving', which creates an ambiguous activation condition. In a skill-routing environment, such broad matching can cause accidental invocation on unrelated requests, making agent behavior less predictable and potentially surfacing irrelevant or unsafe workflow instructions in the wrong context.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger keywords include extremely broad terms such as “self”, “improving”, and “enable”, which are likely to appear in many unrelated prompts. This can cause the skill to activate outside its intended scope, leading to unintended instruction injection into unrelated tasks and reducing reliability of agent behavior.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The enablement condition in the description is broad and ambiguous, covering a wide range of loosely related requests such as software-and-data, self, and improving. Ambiguous activation boundaries increase the chance of accidental invocation, which can misroute user requests and apply the wrong workflow or assumptions.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The example trigger phrases are written as highly generic everyday requests like “Help me...” and “I need a practical workflow...”, which overlap heavily with normal user language. These examples effectively broaden the activation surface and may encourage matching on common phrasing rather than the specialized intent of the skill.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The default prompt and invocation language are highly generic ('help me', 'fixing bugs', broad software/data/self-improving terms), which increases the chance of accidental or implicit invocation during unrelated user requests. Because implicit invocation is enabled, this broad phrasing can cause the skill to trigger on common speech patterns, leading to unintended delegation, prompt-surface expansion, and possible misuse of the skill in contexts the user did not explicitly request.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrases include broad everyday terms such as "help me," "I need," and generic topic words, which can cause the skill to activate in contexts far beyond the intended requirement. In an agent ecosystem, over-broad activation can route unrelated user requests into this skill, leading to incorrect handling, prompt collisions, or unintended execution paths in downstream workflows.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.