Back to skill

Security audit

USA Business Migration Planner

Security checks across malware telemetry and agentic risk

Overview

This skill is not destructive, but its name and routing describe a business migration planner while its actual content is for MacBook monitor recommendations, which could misroute users.

Review before installing. The artifact appears to be a lightweight advice skill, not malware, but it should be renamed and scoped to MacBook Pro external monitor recommendations, or rewritten to actually cover USA business migration. Disable implicit invocation or narrow triggers before using it in a multi-skill environment.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (22)

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The skill presents itself as a USA business migration planner, but the README content actually targets MacBook Pro external monitor recommendations. This identity/behavior mismatch can mislead routing, review, and user trust decisions, and may allow a skill to be invoked or approved under false pretenses. In a skill ecosystem, deceptive or inconsistent packaging is dangerous because operators and users rely on metadata to understand what a skill will do.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The README presents the skill as a 'USA Business Migration Planner' while nearly all demand evidence, triggers, and examples are about recommending external monitors for a MacBook Pro M4 Pro. This mismatch is dangerous because it obscures the skill’s actual behavior and can cause users or orchestrators to invoke the wrong capability, undermining trust, review quality, and policy enforcement.

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The top-level label contradicts the body of the README, indicating inconsistent documentation of the skill’s purpose. Even if not overtly malicious, such contradictions increase the chance of incorrect routing, reviewer misunderstanding, and accidental activation in inappropriate contexts.

Intent-Code Divergence

High
Confidence
98% confidence
Finding
The skill claims to be a 'USA Business Migration Planner' but its manifest and body actually target MacBook Pro external monitor recommendations. This identity mismatch can cause incorrect routing, trust confusion, and policy bypass in systems that rely on metadata to decide when a skill should activate or what permissions and review standards apply.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The manifest description and workflow describe a broad generic-help skill for MacBook monitor advice rather than the declared business-migration domain. This creates a capability mismatch that can lead to unintended invocation, user deception, and misuse of the skill outside its reviewed scope, especially if orchestration depends on manifest labels.

Description-Behavior Mismatch

Medium
Confidence
97% confidence
Finding
The skill’s declared identity and title say it is a USA business migration planner, but the actual description and operational content are about MacBook Pro external monitor recommendations. This mismatch can cause the agent to invoke the wrong skill, mislead reviewers, and hide unsafe or irrelevant behavior under a misleading label.

Intent-Code Divergence

Medium
Confidence
96% confidence
Finding
The inline documentation is self-contradictory: it presents business migration planning in the heading while the workflow, examples, and triggers are for monitor recommendation help. Such contradictions increase the chance of erroneous routing, user confusion, and policy bypass because operators cannot reliably determine the skill’s intended scope.

Description-Behavior Mismatch

High
Confidence
99% confidence
Finding
The manifest presents a skill named 'USA Business Migration Planner' while its description and default prompt are about recommending external monitors for a MacBook Pro in Chinese. This identity mismatch can mislead routing and users, causing the wrong skill to be invoked under false pretenses and undermining trust boundaries around what the skill is supposed to do.

Description-Behavior Mismatch

High
Confidence
99% confidence
Finding
The skill metadata names a USA business migration planner, but the documented behavior and triggers are for MacBook Pro external monitor recommendations. This identity/behavior mismatch can cause the wrong skill to be invoked or trusted under false pretenses, which is dangerous in agentic systems because routing, approvals, and user expectations may depend on the declared skill purpose.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger sentence uses a broad natural-language phrase ('Help me ...') that overlaps with ordinary user requests and can cause accidental invocation. Overbroad triggers increase the chance that the wrong skill activates in unrelated conversations, leading to confusion, misrouting, or unintended execution of skill instructions. The danger is amplified here because the skill is already mislabeled, so accidental invocation may surface the wrong workflow under an unrelated identity.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The invocation section does not clearly define when the skill should or should not be triggered, leaving scope ambiguous. Ambiguous trigger boundaries can cause unintended activation, tool misselection, and policy bypass-by-confusion when a general request is interpreted as permission to use this skill. Given the mismatch between title and content, unclear scope makes the skill more dangerous because reviewers and orchestrators cannot reliably infer intended use.

Vague Triggers

High
Confidence
89% confidence
Finding
The trigger phrases are broad and generic enough to match ordinary user requests, especially with terms like 'general-help' and generic workflow language. This can cause the skill to activate unexpectedly, increasing the risk of prompt hijacking, wrong-tool invocation, or user confusion in unrelated conversations.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger description is overly broad, including generic terms like 'general-help' and common request patterns that could match many unrelated user prompts. Overbroad activation increases the chance this skill intercepts conversations it was not designed for, causing incorrect responses, prompt-surface expansion, and possible policy evasion through unintended routing.

Vague Triggers

High
Confidence
95% confidence
Finding
The keyword list contains ambiguous everyday terms such as 'pro' and 'typec' without constraints, making accidental or adversarial triggering much more likely. In a multi-skill environment, this can hijack normal conversations and route users into an irrelevant or misleading skill path.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The example triggers use generic phrasing like 'Help me' and 'I need a practical workflow,' which encourages broad matching behavior and weakens the boundary between this skill and normal assistant behavior. While less severe than metadata mismatch, it still increases misrouting risk and makes skill invocation easier to manipulate.

Vague Triggers

High
Confidence
95% confidence
Finding
The activation guidance includes extremely broad terms such as general-help, qna, and pro, which can match many unrelated user requests. Overbroad triggers make accidental activation likely, causing this skill to intercept requests outside its domain and potentially override more appropriate safeguards or workflows.

Vague Triggers

High
Confidence
98% confidence
Finding
The keyword list contains ambiguous tokens like general-help, qna, macbook, and pro, which are too generic to safely distinguish the intended task. In an agent environment, this can cause frequent unintended invocation and prompt the model to follow irrelevant instructions in contexts where the skill should not apply.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The example trigger phrases are open-ended and define only positive activation cases, without boundaries for exclusion or scope control. This trains activation systems and maintainers to invoke the skill too broadly, increasing the chance of misrouting user requests and producing irrelevant or misleading assistance.

Vague Triggers

High
Confidence
95% confidence
Finding
The default prompt uses very broad language ('Use $usa-business-migration-planner to help me...') tied to generic help behavior, while implicit invocation is enabled. That combination increases the chance the skill is triggered for unrelated requests, potentially injecting off-topic instructions or hijacking normal assistant behavior without clear user intent.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The default prompt embeds a specific Chinese query about MacBook Pro external monitor recommendations regardless of the user's language or request. This can override user intent, create confusing cross-language behavior, and steer model output toward content the user did not ask for.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger sentence begins with a very broad everyday phrase ('Help me ...'), making accidental or overbroad invocation likely. In an agent environment, such generic phrasing can hijack unrelated user requests and route them into an unintended skill, producing irrelevant or unsafe outputs.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger 'I need a practical workflow for ...' is ambiguous and describes a generic task shape rather than a clearly bounded subject area. This increases the chance of unintended activation whenever a user asks for a workflow, even when the request is unrelated to MacBook displays.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.