Back to skill

Security audit

USA Business Migration Planner

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a generic vibe-coding workflow published under an unrelated USA business migration name, with broad implicit activation that could route users to the wrong guidance.

Review before installing. The artifact does not show malware-like behavior, but its name, description, and triggers do not reliably describe what it does. Install only if you want a generic coding-workflow helper, and consider renaming it and narrowing its triggers first.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (14)

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The skill's declared identity and purpose are materially inconsistent with its actual documented behavior. This kind of mismatch can cause the wrong skill to be invoked under false expectations, undermining user trust and potentially routing unrelated requests into a workflow the user did not intend to run.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The skill’s name and heading claim it is a USA business migration planner, but the body actually targets an unrelated 'vibe coding' workflow. This mismatch can cause the wrong skill to activate or mislead users and downstream agents into applying irrelevant instructions, creating a prompt-routing and trust-boundary failure. In this context, the contradiction makes the skill more dangerous because broad invocations may pull in behavior the user did not request.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The skill’s declared identity says it is a USA business migration planner, but the body actually describes a generic vibe-coding workflow skill. This mismatch can cause incorrect routing, user deception, or accidental invocation in the wrong context, which is especially risky in agent ecosystems where metadata drives trust and execution decisions.

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The manifest presents the skill as a 'USA Business Migration Planner' while the description and default prompt refer to an unrelated topic about 'vibe coding' in Chinese. This mismatch can mislead users and orchestration systems about the skill’s actual purpose, increasing the risk of unintended invocation, trust abuse, or routing sensitive requests to the wrong skill.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The skill metadata says it is a USA business migration planner, but the referenced plan implements a vibe-coding assistance workflow instead. This identity/behavior mismatch can cause incorrect routing, misleading user trust, and unsafe invocation in contexts where users or higher-level agents expect a very different domain, which is a real security and safety issue in agent ecosystems.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The triggering terms are broad and generic, increasing the chance that this skill activates for common coding or creation requests unrelated to its stated purpose. In combination with the identity mismatch, this broad routing behavior makes accidental invocation more likely and can misdirect user workflows or outputs.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrases are broad, generic, and overlap with ordinary user requests such as 'create', 'coding', and 'practical workflow'. This can cause the skill to activate unexpectedly for unrelated prompts, leading to inappropriate routing, prompt-context injection into unrelated tasks, or unwanted skill execution surface expansion.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger keywords are extremely broad and include generic terms like 'create', 'coding', 'skill', and 'claude', which can cause accidental invocation in many unrelated conversations. Overbroad activation increases the chance of context hijacking, irrelevant instruction injection, and unintended application of this mismatched skill. Because the skill content is already inconsistent, broad triggers amplify the routing risk significantly.

Vague Triggers

High
Confidence
92% confidence
Finding
The description says to use the skill when a user asks for broad categories like 'software-and-data' or 'coding', which is too ambiguous to safely scope invocation. Ambiguous conditions can cause the system to route unrelated tasks into this skill, exposing users to irrelevant or conflicting guidance. The danger is elevated here because the declared skill purpose does not match its actual content, making misrouting more harmful.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger keywords are overly broad and common terms such as 'create', 'coding', and 'skill', making accidental activation likely. Over-triggering can inject irrelevant instructions into unrelated conversations, confuse users, and cause the agent to apply the wrong workflow or expose outputs outside the intended scope.

Vague Triggers

High
Confidence
97% confidence
Finding
The default prompt is vague and broad, and allow_implicit_invocation is enabled, allowing the platform to trigger this skill under weak matching conditions. Combined with inconsistent metadata, this can cause accidental activation for unrelated requests, leading to wrong-tool usage, privacy exposure in forwarded user context, or policy bypass through overbroad routing.

Natural-Language Policy Violations

Medium
Confidence
83% confidence
Finding
The manifest mixes English and Chinese in user-facing activation text without declaring locale expectations or offering a language selection path. This can confuse both users and automated routing logic, making matching less predictable and increasing the chance of incorrect invocation or misunderstanding of the skill’s real function.

Vague Triggers

High
Confidence
91% confidence
Finding
The trigger sentence uses a broad everyday phrase ('Help me ...') that can match ordinary user requests far outside the intended scope. Overbroad activation increases the chance that the skill is invoked unexpectedly, which can hijack routing, interfere with other skills, or surface irrelevant instructions in unrelated conversations.

Vague Triggers

Medium
Confidence
88% confidence
Finding
These trigger sentences are ambiguously scoped and do not define concrete activation boundaries, so the skill may activate on loosely related requests. In an agent setting, ambiguous routing rules can cause misfires, confusing outputs, and unreviewed cross-domain behavior, especially given the mismatch between the skill's declared name and actual function.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.