Back to skill

Security audit

USA Business Migration Planner

Security checks across malware telemetry and agentic risk

Overview

This skill is not destructive, but it is mislabeled as USA business migration while actually guiding Estonia e-Residency and Estonian OÜ planning, with broad implicit triggers that could route users to the wrong advice.

Review this before installing. It appears non-executable and not malicious, but the publisher should rename and scope it to Estonia e-Residency/Estonian OÜ, narrow the triggers, and add explicit jurisdiction limits before users rely on it for business migration planning.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (13)

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The skill’s name and stated domain suggest USA business migration planning, but the actual content is about Estonia e-Residency and operating an Estonian OÜ. This mismatch can misroute user requests, cause inappropriate invocation, and undermine trust and safety boundaries because users and orchestrators may rely on the title/manifest to decide when the skill should run.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The skill's identity claims 'USA business migration' while the actual content is about Estonia e-Residency and operating an Estonian OÜ. This mismatch can cause the agent to invoke the wrong skill for unrelated user requests, producing irrelevant or misleading business guidance and weakening trust and routing integrity.

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The heading 'USA Business Migration Planner' directly contradicts the remainder of the file, which documents an Estonia-focused workflow. In agent systems, contradictory labels increase the chance of accidental activation, operator confusion, and unsafe reliance on advice intended for a different jurisdiction and business regime.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill is labeled as a USA business migration planner, but its actual content concerns Estonia e-Residency and operating an Estonian OÜ. This mismatch can cause the wrong skill to be invoked or trusted in the wrong context, leading users to receive materially irrelevant business, legal, or operational guidance.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrases are broad, malformed, and ambiguous enough that the skill could be invoked for loosely related requests that do not match its real scope. In an agent environment, this increases the chance of unintended activation, confusing outputs, and potentially bypassing more appropriate domain-specific skills or review steps.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are generic and malformed enough that they can match loosely related user requests, increasing the chance of unintended skill activation. In an agent environment, over-broad invocation can route users into the wrong workflow, causing confused-deputy behavior, irrelevant guidance, or accidental processing of requests outside the skill’s intended scope.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger description is broad enough to match generic requests for workflows, artifacts, checklists, or analysis, even when the user is not asking about Estonia e-Residency. Over-broad activation can route normal conversations into a niche legal-operational skill, causing confusing or incorrect guidance in sensitive business contexts.

Vague Triggers

Medium
Confidence
90% confidence
Finding
Keywords such as 'running' and 'surprised' are common in ordinary speech and can trigger the skill outside its intended domain. This increases the risk of inappropriate skill invocation and delivery of jurisdiction-specific business advice where it does not belong.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger keywords are broad and overlap with ordinary discussion terms such as 'running' and 'surprised,' which can cause unintended activation. Over-broad routing increases the chance that unrelated user conversations are hijacked by this skill, producing irrelevant or misleading advice.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The sample trigger phrases are themselves loosely defined and normalize matching on generic wording rather than a bounded intent. This encourages over-triggering behavior and makes it more likely the skill activates outside its intended domain, reducing reliability and potentially confusing users.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The skill’s display text and default prompt are vague, truncated, and broad enough to create unclear invocation boundaries. Combined with allow_implicit_invocation=true, this increases the chance the agent will invoke the skill for loosely related requests, causing unintended handling of user tasks, incorrect delegation, or policy bypass through overbroad routing.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger sentence is so generic and malformed that it can overlap with ordinary user phrasing, causing the skill to activate outside its intended scope. In an agent system, overbroad activation can inject irrelevant business-planning behavior into unrelated conversations and create prompt-routing confusion or unintended tool use.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The activation examples are ambiguous, truncated, and malformed, making it unclear when the skill should run and increasing the chance of accidental invocation. In orchestration environments, unclear routing criteria can lead to inappropriate context capture, wrong workflow execution, or user confusion about why this skill was selected.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.