Back to skill

Security audit

USA Business Migration Planner

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a prompt-cache workflow helper published under an unrelated business-migration name, with broad implicit activation that could misroute user requests.

Review this skill before installing. It does not show malware-like behavior, but its public identity does not match its actual instructions, and it may be selected for unrelated requests because its triggers are broad.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (15)

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The skill metadata and README title claim this is a 'USA Business Migration Planner', but the body describes Claude Code prompt-cache guidance. This mismatch can cause incorrect routing, user deception, or accidental invocation in unrelated contexts, which is a real security and trust boundary issue for agent skill selection. The odd topic substitution also increases suspicion because misleading labeling is a common way to smuggle unintended behavior past review.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The README presents the skill as a 'USA Business Migration Planner' while the actual described behavior is about Claude Code Prompt Cache workflows. This identity mismatch can cause incorrect routing or activation, leading users to invoke a skill under false assumptions and potentially receive unrelated or unsafe guidance; deceptive or inconsistent labeling is especially risky in agent ecosystems where names and descriptions influence automatic tool selection.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The skill is named 'usa-business-migration-planner' but the body and requirement describe an unrelated topic about Claude Code prompt caching. This identity mismatch can cause the wrong skill to be invoked or trusted under false expectations, which is dangerous in agent systems because users and orchestrators may grant broader authority or relevance based on the misleading name.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The inline documentation says 'USA Business Migration Planner' while the substantive requirement is about Claude Code prompt cache behavior, creating contradictory identity signals inside the same skill. Such contradictions increase the risk of misrouting, hidden intent, and operator confusion, especially when an agent uses headings and embedded docs to decide applicability.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The skill name and stated purpose claim 'USA Business Migration Planner', but the actual body is about Claude Code prompt cache workflows. This identity mismatch can cause the skill to be invoked in the wrong context, bypass user expectations, and enable deceptive routing or hidden behavior under an unrelated label. Because users and orchestrators often rely on metadata for trust and selection, mislabeled skills are a meaningful security and integrity risk.

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The manifest presents the skill as a 'USA Business Migration Planner' while the description and default prompt discuss Claude Code prompt caching. This identity/purpose mismatch can mislead routing and users, causing the skill to be invoked in unrelated contexts and increasing the chance of unsafe or unintended behavior.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger sentences are broad enough that the skill could activate on vague requests for help or workflows without clear scope checks. In an agent environment, overbroad activation can hijack unrelated user requests, causing the wrong skill to run, produce misleading guidance, or interfere with higher-priority safety constraints. The context makes this more dangerous because the skill is already mislabeled, so broad triggers amplify the risk of accidental or deceptive invocation.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrases are broad enough to match common user requests, increasing the chance the skill is invoked outside its intended scope. Over-broad activation can hijack unrelated conversations, inject irrelevant instructions into agent behavior, and degrade trust or safety when the wrong skill handles a task.

Vague Triggers

High
Confidence
97% confidence
Finding
The top-level description uses very broad trigger language such as 'software-and-data', 'code', and 'needs a practical workflow,' which overlaps with many ordinary requests. Overbroad routing criteria can make this skill activate for unrelated prompts, exposing users to irrelevant or misleading instructions and potentially interfering with safer, better-scoped skills.

Vague Triggers

High
Confidence
98% confidence
Finding
The keyword triggers include generic terms like 'claude', 'code', 'prompt', and 'cache', which are ambiguous and likely to match a wide range of unrelated conversations. In a skill system, this can lead to unintended activation at scale, causing cross-domain contamination and making it easier for a mislabeled skill to hijack normal workflows.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger keywords are excessively broad, including generic terms like 'code', 'claude', and 'prompt', which can match many ordinary conversations unrelated to the intended task. Overbroad activation increases the chance of unintended invocation, causing the skill to inject irrelevant instructions or override more appropriate skills, which can degrade safety and user control.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The default prompt uses a broad, unclear invocation phrase tied to a loosely described requirement, which makes it hard to determine when the skill should activate. Ambiguous triggers can cause inappropriate invocation on unrelated user requests, exposing users to irrelevant instructions or misrouted assistance.

Vague Triggers

Medium
Confidence
93% confidence
Finding
Implicit invocation is enabled without any specific activation criteria, so the platform may auto-select this skill based on weak or noisy matches. In combination with the manifest's mismatched identity, this raises the risk of unintended activation and incorrect guidance in unrelated conversations.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger sentence uses a very broad everyday phrase ('Help me ...') tied to a long requirement string, which can cause the skill to activate in contexts far beyond the intended topic. Overbroad activation increases the chance of inappropriate routing, prompt hijacking via incidental phrase matches, and unintended invocation on unrelated user requests.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger sentence ('I need a practical workflow for ...') is ambiguous and insufficiently scoped, so it may match many benign requests for workflows unrelated to Claude Code prompt caching. In a skill-routing system, ambiguous triggers can cause misselection of this skill, leading to incorrect handling, leakage of irrelevant instructions, or user confusion that degrades safety controls.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.