Back to skill

Security audit

USA Business Migration Planner

Security checks across malware telemetry and agentic risk

Overview

The skill appears non-destructive, but its name and automatic routing metadata do not match what it actually does, so users should review it before installing.

Install only if you intend to use this as a Qwen Image 3 product and SEO review workflow, not as a USA business migration planner. The publisher should rename and rescope the skill, narrow the trigger language, and consider disabling implicit invocation until the identity and routing metadata are consistent.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (20)

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The README content describes a Qwen Image product/SEO workflow while the skill is named as a USA business migration planner, creating a strong identity mismatch. This can cause the wrong skill to be invoked or trusted under false pretenses, increasing the risk of misrouting user requests, policy bypass through misclassification, or supply-chain style confusion in skill registries.

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
The README presents the skill as a 'USA Business Migration Planner' while the actual described demand is for a Qwen Image 3 product/SEO workflow. This semantic mismatch can cause the wrong skill to be invoked or trusted under false pretenses, which is dangerous in agentic systems because users and orchestration layers may rely on the declared skill identity to decide what capabilities are safe to run.

Intent-Code Divergence

High
Confidence
93% confidence
Finding
The section explaining how the skill satisfies the need describes a generic workflow for handling the Qwen Image/SEO request, not the named business-migration domain. In a skill-routing environment, this inconsistency increases the risk of prompt confusion, improper delegation, and accidental access to irrelevant or unsafe workflows because the documentation no longer reliably communicates the skill's true behavior.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The skill’s declared identity ('usa-business-migration-planner') materially conflicts with its actual content, which is about Qwen Image 3 product/SEO advice. This can cause the wrong skill to be invoked, mislead users and downstream agents, and weaken trust and policy routing because decisions may be made based on the name rather than the real behavior.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The skill’s declared identity says it is a USA business migration planner, but the body actually targets Qwen Image 3 product/SEO advice. This semantic mismatch can cause the orchestrator or user to invoke the skill in the wrong context, leading to misrouting, incorrect automation behavior, and reduced trust in safety boundaries.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The document title reinforces a false capability label while the actual requirement and workflow serve a different topic. In skill-routing systems, contradictory naming can mislead selection logic and operators, increasing the chance of inappropriate activation and unsafe or irrelevant outputs.

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The manifest presents the skill as a USA business migration planner, but its default prompt and description route users toward unrelated Qwen Image 3 product/SEO advice. This semantic mismatch can misinvoke the skill in the wrong contexts, confuse users, and bypass meaningful user intent boundaries, especially when downstream systems rely on manifest text for routing or trust decisions.

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
The documented behavior is a generic workflow for product/SEO advice around a Qwen Image tool site, while the skill metadata name implies an unrelated USA business migration planner. This identity/behavior mismatch can cause incorrect routing, user confusion, and unsafe invocation of the skill in contexts where its actual scope is not expected, increasing the chance of prompt-trigger abuse or policy bypass through misclassification.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger sentences are broad enough to match ordinary user phrasing, which can cause unintended activation of this skill outside its legitimate scope. In an agent environment, overbroad triggers expand the skill's reach and can hijack unrelated conversations, leading to incorrect guidance, unexpected tool use, or exposure of users to irrelevant or unsafe workflows.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger phrases use broad, natural language such as 'Help me' and 'I need a practical workflow,' which can match many unrelated user requests. In agent systems, overly generic activation patterns can lead to unintended invocation of the wrong skill, producing confusing outputs or causing a mismatched workflow to handle sensitive user tasks.

Vague Triggers

High
Confidence
96% confidence
Finding
The top-level description contains very broad trigger terms like 'software-and-data', 'create', 'qwen', and 'image', which are generic enough to match many unrelated user requests. Overbroad matching increases unintended invocation risk, causing this skill to intercept prompts outside its intended scope and potentially override more appropriate skills or workflows.

Vague Triggers

High
Confidence
97% confidence
Finding
The keyword triggers ('software-and-data', 'v2ex', 'create', 'qwen', 'image', 'seo', 'prompts') are too generic and lack gating conditions, so the skill may activate on many unrelated conversations. In an agentic environment this can cause prompt-routing errors, context contamination, and reduced reliability of task selection.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger keywords include broad generic terms like 'create', 'image', and 'seo', which can cause accidental activation for many unrelated requests. Overbroad triggering expands the skill’s effective scope beyond its intended use and can override more appropriate skills or inject irrelevant workflows into user interactions.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The invocation condition in the description is vague and lacks clear boundaries, making it difficult to determine when the skill should or should not run. Ambiguous eligibility criteria increase misfires and can cause this skill to intercept requests outside its safe or useful domain.

Vague Triggers

Low
Confidence
84% confidence
Finding
The example trigger phrases are phrased as broad everyday requests and do not include constraints that limit activation to the intended scenario. This makes accidental matching more likely, especially in systems that rely on example utterances for routing behavior.

Vague Triggers

High
Confidence
93% confidence
Finding
The default prompt uses a vague invocation phrase and broad task framing, making it unclear when the skill should activate and what it is authorized to do. Ambiguous prompts increase the chance of accidental invocation, scope creep, and unsafe task capture by the wrong skill, especially in automated agent-selection pipelines.

Vague Triggers

High
Confidence
98% confidence
Finding
Enabling implicit invocation without tight trigger constraints allows the skill to be selected automatically for loosely related requests. In this file, that risk is amplified by the already-misaligned branding and broad prompt text, increasing the likelihood of unauthorized or confusing auto-activation in unrelated conversations.

Natural-Language Policy Violations

Medium
Confidence
82% confidence
Finding
The prompt mixes English with Chinese content without explaining locale expectations or obtaining user opt-in. This can cause incorrect routing, degraded comprehension, and mismatched user experiences, particularly when language cues are used by agents to infer relevance or authority.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger sentence starts with an overly broad everyday phrase ('Help me ...'), which risks activating the skill for ordinary user requests that were not intended to invoke this specific capability. Overbroad activation can lead to unintended handling of unrelated prompts, making routing less predictable and easier to manipulate.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger sentence is ambiguous and does not define clear activation boundaries, so the skill may be selected for vague workflow-related requests without sufficient relevance. Ambiguous trigger logic increases accidental invocation and creates opportunities for adversarial phrasing to steer the agent into the wrong skill.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.