Back to skill

Security audit

USA Business Migration Planner

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a harmless documentation workflow, but its name and automatic triggers do not match its actual CDN-planning content, so it should be reviewed before installation.

Install only if you actually want a CDN/vendor-selection planning helper. Before broad use, rename the skill to match the CDN purpose, narrow its triggers, and consider disabling implicit invocation so unrelated requests are not routed into it. I found no executable code, credential handling, persistence, or destructive behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (15)

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The README claims to be a 'USA Business Migration Planner' but the actual content, evidence, and triggers are about CDN provider selection and Cloudflare timeout limitations. This mismatch can cause the wrong skill to be invoked or trusted under false pretenses, increasing the chance of unintended behavior, policy bypass through misclassification, and user deception even if no direct code execution is present.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The skill is presented as a 'USA Business Migration Planner' but its actual behavior and examples are about choosing CDN alternatives to Cloudflare. This identity mismatch can cause the agent to invoke the skill in the wrong contexts and mislead users or downstream systems about the skill’s purpose, which is dangerous because trust and routing decisions are often based on name and description metadata.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The documented title/identity contradicts the task content, creating ambiguity about what the skill is supposed to do. In agent ecosystems, contradictory identity information can lead to accidental invocation, user confusion, and policy bypass if a harmless-looking title masks unrelated operational behavior.

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
The skill metadata presents a USA business migration planner, but the documented requirement is about CDN vendor selection and timeout limits. This mismatch can cause the wrong skill to activate or be trusted under false pretenses, which is dangerous in an agent system because it weakens user intent matching and can route requests into unrelated behavior.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger sentence uses a very broad help-request pattern ('Help me...') that resembles normal conversation and can cause the skill to activate when the user did not intend to invoke it. In an agent environment, overly generic triggers increase the chance of unintended routing, causing the wrong workflow to run and potentially producing irrelevant or confusing actions.

Vague Triggers

Medium
Confidence
90% confidence
Finding
This trigger pattern is broad and ambiguous, describing a general need for a 'practical workflow' rather than a clearly bounded CDN selection use case. Such ambiguity can make the skill match unrelated requests, leading to mis-invocation and unreliable behavior in multi-skill systems.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The skill is labeled under the very broad category 'general-help' while also describing a specific CDN-related requirement, creating mismatch and unclear invocation boundaries. Broad categorization in shared agent ecosystems increases accidental selection and may route unrelated user requests into this skill.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrases are broad natural-language requests such as 'Help me...' and 'I need a practical workflow...', which overlap with ordinary user speech. Overbroad activation criteria can cause accidental invocation in unrelated conversations, exposing users to irrelevant or misleading guidance and making prompt-routing easier to manipulate.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger keywords are extremely broad (for example, 'general-help') and can cause the skill to activate for many unrelated conversations. Overbroad activation increases the chance of unintended routing, irrelevant guidance, and prompt-scope confusion, which is a security and reliability issue when skills are selected automatically.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The description says to use the skill when a user asks for several broad topics or 'needs a practical workflow' without clearly limiting the skill to the CDN timeout/vendor-selection scenario. This ambiguous activation language can cause the skill to be invoked outside its intended scope, leading to misapplication and potentially unsafe or misleading outputs.

Natural-Language Policy Violations

Medium
Confidence
79% confidence
Finding
The skill mixes English and Chinese content but does not state how language should be selected or whether outputs should match the user's language. This can cause misunderstanding of requirements, incorrect task routing, or user confusion, especially when automated systems rely on the metadata for matching and response generation.

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger keywords include generic terms like 'general-help' and common conversational tokens that are likely to match many unrelated user requests. Overbroad triggers increase the chance that this mismatched skill is auto-selected unexpectedly, amplifying the risk of incorrect guidance, prompt-space interference, or skill routing manipulation.

Vague Triggers

High
Confidence
95% confidence
Finding
The default prompt uses a vague auto-invocation phrase tied to a broad user need, which can cause the skill to trigger in contexts the user did not clearly intend. Because implicit invocation is enabled, this increases the chance of inappropriate routing, accidental data exposure to the skill, or user confusion about why this skill was selected.

Vague Triggers

High
Confidence
90% confidence
Finding
The trigger phrase is so broad that it can match ordinary requests like 'Help me' without sufficient domain constraints. In an agent environment, this can cause unintended invocation, prompt hijacking of unrelated user tasks, or privilege expansion where a loosely related skill inserts itself into conversations it should not handle.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The invocation guidance lacks clear boundaries on when the skill should and should not activate, and mixes broad keywords with templated trigger sentences. That ambiguity increases accidental activation and makes it easier for unrelated prompts to be captured by this skill, especially given the existing mismatch between stated skill purpose and actual content.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.