Back to skill

Security audit

USA Business Migration Planner

Security checks across malware telemetry and agentic risk

Overview

The skill does not appear destructive, but its name, purpose, triggers, and implicit invocation settings are materially inconsistent and could route users to the wrong behavior.

Do not install this version as-is unless you are prepared for ambiguous routing. The publisher should rename and scope the skill to the actual albums-view filtering use case, or replace the body content so it genuinely supports USA business migration planning, then disable or narrow implicit invocation and generic trigger terms.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (20)

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The README content is materially inconsistent with the skill’s stated identity: it presents a 'USA Business Migration Planner' while describing an unrelated albums-view filtering workflow. This kind of semantic mismatch can mislead users and routing systems into invoking the skill in unintended contexts, increasing the chance of inappropriate outputs, prompt confusion, or abuse through deceptive packaging.

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
The skill’s declared identity and its actual body content describe materially different purposes, which can mislead routing, reviewers, and users about what the skill will do. This kind of identity mismatch increases the chance that the skill is invoked in the wrong context and can hide unintended behavior from normal scrutiny.

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The manifest advertises a music-library filtering workflow while the visible skill identity claims business migration planning, creating a deceptive or at least confusing interface boundary. Such inconsistencies can cause incorrect activation, bypass human review expectations, and make downstream systems trust a capability different from what is actually implemented.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The skill is named and presented as a USA business migration planner, but its actual content is about filtering singles in an Albums view. This semantic mismatch can cause the wrong skill to be invoked or trusted under false pretenses, leading to inappropriate behavior, user confusion, and potential routing or authorization mistakes in larger agent systems.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The manifest presents the skill as a 'USA Business Migration Planner,' but the description and default prompt talk about filtering out singles in Albums view, which is unrelated. This identity/behavior mismatch can mislead routing systems and users, causing the skill to be invoked in contexts where its actual behavior is unexpected, increasing the risk of inappropriate activation and unsafe downstream actions.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The skill metadata claims to be a USA business migration planner, but the actual requirement plan is for filtering singles in an albums view. This kind of semantic mismatch can cause the wrong skill to activate in unrelated contexts, leading to unintended behavior, confused routing, and erosion of trust in safety boundaries. The misleading scope is especially concerning because users or orchestrators may invoke the skill based on its declared purpose while receiving unrelated behavior.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The usage section explicitly instructs invoking the business-migration-planner skill for an unrelated albums-filtering task. That creates a direct path for misrouting user requests, causing the wrong skill to be selected and potentially exposing users to irrelevant or unsafe automation outside the intended domain. In agent ecosystems, invocation confusion is a real safety issue because downstream tools often trust documented triggers.

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger phrases are broad natural-language sentences that can match ordinary user requests, which increases the chance of unintended skill activation. In an agent environment, accidental invocation can cause the wrong workflow or instructions to take over user interactions, reducing reliability and potentially enabling prompt-scope interference if the skill contains unsafe guidance.

Vague Triggers

Medium
Confidence
89% confidence
Finding
Labeling the skill as 'general-help' while providing weak trigger constraints creates ambiguous activation scope, making the skill eligible for many unrelated conversations. This broad matching surface is dangerous because it can cause unintentional routing to a mismatched skill, especially when the described requirement is itself inconsistent and loosely defined.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrases and keywords are broad enough to match common requests such as 'help me' or generic workflow asks, which can cause the skill to activate outside its intended domain. In combination with the misleading identity of the skill, this expands the attack surface by enabling unexpected invocation and user confusion.

Vague Triggers

High
Confidence
98% confidence
Finding
The trigger keywords are extremely broad, including common words like 'general-help', 'filter', 'out', and 'related', which are likely to appear in many unrelated conversations. This creates a high risk of accidental or excessive invocation, allowing the skill to intercept requests outside its intended scope and potentially override more appropriate skills.

Vague Triggers

High
Confidence
95% confidence
Finding
The invocation description is vague and expansive, stating the skill should be used for general help and practical workflow support without clear domain boundaries. In context, this is more dangerous because the skill is already mislabeled, so ambiguous invocation criteria increase the chance of this mismatched skill being selected for unrelated requests.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The example trigger sentences use everyday phrasing that does not impose meaningful scope limits, making the skill easier to activate from normal user language. While less severe than the keyword list itself, these examples reinforce overbroad matching behavior and can normalize unsafe routing patterns.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger keywords are overly broad and overlap with common language such as 'general-help', 'filter', 'view', and 'related'. In an agent environment, this increases accidental activation risk, causing the skill to intercept unrelated requests and potentially override more appropriate skills or workflows.

Vague Triggers

High
Confidence
90% confidence
Finding
The invocation criteria in the description are vague and do not clearly define when the skill should or should not run. Ambiguous activation boundaries make misrouting more likely, especially when combined with generic terms, which can result in unintended execution and unreliable agent behavior.

Vague Triggers

High
Confidence
95% confidence
Finding
The default prompt uses generic language such as 'help me' and a broad problem statement, which creates an overly permissive trigger surface. In combination with skill-based routing, ambiguous invocation text can cause accidental activation for unrelated user requests, exposing users to irrelevant or unintended behavior.

Vague Triggers

High
Confidence
98% confidence
Finding
Implicit invocation is enabled even though the manifest does not define clear trigger constraints or a tightly scoped purpose. This makes the skill easier to auto-select for loosely related requests, and the mismatch between identity and behavior further increases the chance of misrouting and unintended execution.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The skill name hard-codes a US-specific locale ('USA') without any indication that the user requested or consented to that jurisdiction. This can bias outputs toward the wrong legal, regulatory, or business context, which is especially risky if users receive planning guidance that does not apply to their actual location.

Vague Triggers

High
Confidence
92% confidence
Finding
An overly broad trigger phrase that overlaps with common speech increases the chance of accidental activation. In a multi-skill agent environment, broad phrases can hijack benign conversations and route them to an irrelevant skill, degrading reliability and potentially bypassing more appropriate safeguards tied to the correct domain.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The activation scope is ambiguous because the keywords and trigger sentences are not tightly constrained to a coherent domain, and they mix generic wording with unrelated subject matter. This makes the skill easier to invoke unintentionally or in the wrong context, which is more dangerous here because the skill already shows strong identity drift between metadata and content.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.