Back to skill

Security audit

USA Business Migration Planner

Security checks across malware telemetry and agentic risk

Overview

The skill does not show malware-like behavior, but its public name says USA business migration while its instructions are for Dify/chat2dify workflows, with broad implicit triggers that could activate unexpectedly.

Install only if you intentionally want a Dify/chat2dify productivity workflow helper, not a USA business migration planner. The publisher should rename and rescope the skill and narrow its triggers before general use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (14)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The README title and apparent skill identity ('USA Business Migration Planner') do not match the actual described functionality, which is Dify/chat2dify workflow support. This kind of identity mismatch can mislead users and orchestration systems into invoking the skill under false assumptions, increasing the chance of inappropriate routing, unsafe trust decisions, or accidental execution in the wrong context.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill is named and presented as a USA business migration planner, but its actual body and workflow target Dify/chat2dify assistance. This mismatch can cause unintended invocation, operator confusion, and misrouting of user requests, which is a security-relevant integrity issue because agents may select and trust the wrong capability based on misleading metadata.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The skill metadata and title present it as a USA business migration planner, but the actual content is about Dify/chat2dify workflow assistance. This mismatch can cause the wrong skill to be invoked, bypass user expectations, and route sensitive user requests into an unrelated prompt path, which is a security and trust-boundary problem rather than a mere documentation issue.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The manifest claims to be a USA business migration planner, but its description and prompt target an unrelated Dify/chat2dify productivity workflow. This mismatch can cause the wrong skill to be invoked for unrelated user requests, leading to deceptive behavior, incorrect task routing, and possible misuse of privileges under a false identity. Because the policy also allows implicit invocation, the context makes this more dangerous by increasing the chance of accidental activation.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The skill is named for 'usa-business-migration-planner' but the requirement document targets an unrelated Dify/chat2dify workflow. This domain mismatch can cause the router or user to invoke the skill under false expectations, leading to unintended handling of requests and increasing the chance of prompt-scope abuse or deceptive activation.

Intent-Code Divergence

High
Confidence
97% confidence
Finding
The document claims to satisfy the manifest requirement while describing a different workflow need entirely. This creates deceptive capability signaling: systems or users may trust the skill for one business purpose while it activates for another, which can bypass normal selection boundaries and produce unsafe or irrelevant outputs.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrases are broad and map to ordinary user language such as 'help me' and 'I need a practical workflow,' which can cause the skill to activate outside its intended scope. In an agent system, this increases the chance of unintended routing, prompt-surface expansion, and the skill being invoked for unrelated requests where its instructions may override more appropriate handling.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The documented trigger phrases are broad and generic enough to match ordinary requests for help, workflows, or implementation support. Overbroad activation can cause the skill to engage unexpectedly, exposing users to irrelevant actions, prompt hijacking opportunities, or unintended processing of unrelated tasks.

Vague Triggers

High
Confidence
93% confidence
Finding
The activation language is excessively broad, including generic phrases like practical workflow, artifact, checklist, analysis, or implementation support, which could cause the skill to trigger for many unrelated tasks. Overbroad routing increases the chance that an irrelevant or misleading skill intercepts user requests, producing unsafe delegation, hidden prompt influence, or incorrect outputs under false pretenses.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger keywords include vague terms such as share, workflow, and dsl, which are common across many benign contexts and do not safely identify the intended skill use case. This makes accidental or adversarial activation easier, especially in multi-skill environments where generic keywords can hijack routing from more appropriate tools.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger keywords include broad, common terms such as "share" and "workflow," which can overlap with ordinary user conversations. Overbroad triggers increase the chance of unintended activation, causing the skill to inject unrelated guidance into sessions and potentially capture context not meant for this skill.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The top-level description says to use the skill for broad categories like work-productivity and implementation support, without clear boundaries. Ambiguous activation scope makes the skill eligible for many unrelated tasks, increasing prompt-routing errors and the possibility that irrelevant instructions influence user interactions.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The invocation text is overly broad, including generic triggers like work-productivity, share, practical workflow, artifact, checklist, analysis, or implementation support. Broad matching criteria can make the skill activate in many unrelated contexts, which is especially risky when the skill's identity and purpose are already inconsistent. In this context, implicit invocation increases the danger because users may be routed into the wrong skill without clear consent.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrases are broad natural-language patterns such as 'Help me' and 'I need a practical workflow,' which can match many ordinary conversations unrelated to the intended task. Overbroad activation increases the risk of accidental invocation, context hijacking, and unreviewed execution of the skill in situations where it should not run.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.