Back to skill

Security audit

USA Business Migration Planner

Security checks across malware telemetry and agentic risk

Overview

This skill is documentation-only, but its name and routing imply USA business migration while its instructions handle unrelated battery-efficiency/general-help requests with very broad implicit activation.

Review this before installing. It does not show malicious code or data access, but the skill should be renamed or rewritten so its title, purpose, triggers, and implicit invocation behavior all match a single narrow use case.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (19)

Description-Behavior Mismatch

High
Confidence
92% confidence
Finding
The README presents a skill named 'USA Business Migration Planner' but the actual requirement and triggers focus on unrelated 'Optimizer Battery Efficiency' general-help behavior. This mismatch can cause the wrong skill to be invoked or trusted under false pretenses, increasing the chance of unintended prompt routing, user confusion, and misuse of the skill in contexts it was not meant to handle.

Description-Behavior Mismatch

Medium
Confidence
97% confidence
Finding
The documentation title says the skill is a USA Business Migration Planner, but the actual content, demand statement, evidence, and trigger phrases describe an unrelated Optimizer Battery Efficiency workflow. This mismatch can mislead users and routing systems about the skill’s true purpose, increasing the chance of unintended invocation and inappropriate trust in the skill’s outputs.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The skill is named and presented as a 'USA Business Migration Planner,' but the manifest and body actually describe an unrelated 'Optimizer Battery Efficiency' requirement. This identity mismatch can cause the wrong skill to be invoked or trusted under false expectations, leading to misrouting, unsafe automation decisions, or concealment of a skill's real behavior.

Intent-Code Divergence

High
Confidence
96% confidence
Finding
The inline documentation contradicts the skill's stated identity by describing generic software-improvement support for battery efficiency instead of USA business migration planning. Contradictory internal guidance increases the chance that agents or maintainers misunderstand what the skill should do, which can be abused to trigger unintended workflows or hide unauthorized repurposing.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The skill’s declared identity ('usa-business-migration-planner') does not match its actual content, which is a generic workflow for 'Optimizer Battery Efficiency.' This kind of semantic mismatch can cause the wrong skill to be invoked, mislead users and downstream systems about the skill’s purpose, and bypass review expectations tied to the stated domain.

Description-Behavior Mismatch

High
Confidence
90% confidence
Finding
The skill metadata and evidence frame this as a battery-efficiency/optimizer-specific helper, but the implementation plan is a generic request-handling workflow that can be invoked under a misleading domain label. This mismatch can cause incorrect routing, overbroad applicability, and user reliance on outputs that are not specialized for the advertised task, weakening trust and potentially bypassing safer domain-specific review or constraints.

Description-Behavior Mismatch

Medium
Confidence
88% confidence
Finding
The usage signals and trigger sentences advertise handling optimizer battery efficiency requests, but the actual behavior routes to a broad general-help flow. This creates deceptive activation semantics: users or orchestrators may invoke the skill for a sensitive or technical domain expecting specialized logic, while receiving generic outputs not tailored to that context.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger keywords and phrases are extremely broad, including common words like 'general-help', 'would', 'suggest', and 'now', which can match ordinary user requests unrelated to this skill. Overbroad activation increases the likelihood of unintended invocation, prompt hijacking of unrelated tasks, and interference with more appropriate skills or baseline assistant behavior.

Vague Triggers

Medium
Confidence
86% confidence
Finding
Classifying the skill under a generic 'general-help' category without clear boundaries makes its activation scope ambiguous. In combination with the unclear business-vs-battery purpose, this broad categorization raises the risk that the skill will be selected in unrelated contexts, producing irrelevant or unsafe guidance.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger keywords and phrases are extremely broad, including common words like 'would', 'suggest', and 'now', plus generic help terms. This can cause the skill to activate during ordinary conversation unrelated to its intended scope, creating prompt-squatting behavior and increasing the risk of user confusion or unintended task interception.

Vague Triggers

High
Confidence
99% confidence
Finding
The trigger keywords include extremely broad terms such as 'would' and 'now,' which overlap with ordinary conversation. This makes accidental activation likely and can cause the skill to intercept unrelated requests, expanding its reach far beyond its intended scope.

Vague Triggers

High
Confidence
97% confidence
Finding
The manifest description defines activation conditions using broad categories like 'general-help' and common words such as 'optimizer,' 'battery,' 'efficiency,' and 'would,' without clear boundaries. Ambiguous routing criteria can cause this skill to activate on many unrelated prompts, creating opportunities for prompt hijacking, user confusion, and unsafe workflow substitution.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The example trigger sentence starts with the generic phrase 'Help me,' which is common in ordinary user requests. Example triggers often influence routing behavior and reviewer expectations, so using such a generic pattern increases the risk of broad unintended activation.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger keywords include extremely broad everyday words such as 'would' and 'now,' making accidental invocation very likely. Over-broad triggers can cause this skill to activate in unrelated conversations, creating prompt-routing confusion, unexpected behavior, and potential interference with safer or more relevant skills.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The usage condition in the description is vague and lacks clear scope boundaries, so the system may apply the skill to loosely related requests. Ambiguous activation criteria increase the chance of unintended routing and make it harder for users and reviewers to predict when the skill will take control.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The default prompt uses a broad, generic invocation phrase ('Use $usa-business-migration-planner to help me...') tied to vague trigger terms, which can cause the skill to activate in contexts unrelated to its intended purpose. This increases the risk of unintended routing, prompt confusion, or the skill being invoked for mismatched user requests, especially because the described capability and the prompt content appear semantically inconsistent.

Vague Triggers

Medium
Confidence
96% confidence
Finding
Enabling implicit invocation without clear activation boundaries allows the system to auto-select this skill based on loosely related language, even when the user did not explicitly request it. Because the metadata mixes unrelated themes ('USA Business Migration Planner' versus 'Optimizer Battery Efficiency'), the chance of accidental invocation and unsafe prompt routing is higher than normal.

Vague Triggers

High
Confidence
93% confidence
Finding
An overly broad trigger phrase increases the chance of accidental or inappropriate activation during ordinary conversation. In an agent environment, this can cause the wrong skill to intercept user intent, leading to confused task routing, unintended actions, or suppression of better-matched and safer skills.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The activation guidance is underspecified and lacks clear boundaries on when the skill should run, making it easier for generic language to trigger it outside its intended domain. Because the skill is already semantically mismatched, weak trigger constraints amplify the risk of misrouting and low-quality or context-inappropriate responses.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.