Back to skill

Security audit

USA Business Migration Planner

Security checks across malware telemetry and agentic risk

Overview

The skill is labeled as a USA business migration planner but actually routes broad help requests into unrelated Claude/Bool promotional workflow content.

Do not install this as a USA business migration planner. It has no dangerous code, but its name and invocation metadata do not match its behavior, so it could activate for broad help requests and steer the agent toward unrelated promotional Claude/Bool content.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (21)

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The README claims to be a USA business migration planner, but the actual content is a generic workflow centered on unrelated Claude/Bool promotional material. This mismatch can misroute user requests, bypass user expectations and review assumptions, and indicates the skill may be disguising its real purpose, which is especially risky when activation is driven by metadata and trigger text.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The README’s title and stated purpose claim a USA business migration planning skill, but the actual content, evidence, and triggers are centered on Claude/Bool promotion posts and related traffic. This mismatch can mislead users and routing systems into invoking the skill in unintended contexts, increasing the chance of deceptive activation, policy bypass, or misuse under a benign-looking label.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The skill presents itself as a USA business migration planner, but its manifest and workflow are actually centered on unrelated promotional V2EX/Claude reseller content. This deceptive mismatch can cause the skill to activate in the wrong contexts and deliver spammy or policy-bypassing content under a trusted label, which is a strong indicator of disguised or repurposed malicious behavior.

Intent-Code Divergence

High
Confidence
97% confidence
Finding
The title claims the skill is for USA business migration planning, while the documented requirement and trigger content concern unrelated Chinese-language promotional material. This contradiction is dangerous because it obscures the skill's real behavior from reviewers and routing systems, increasing the likelihood of covert activation and misuse.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The skill’s declared identity and its actual behavior materially diverge: it is labeled as a USA business migration planner but operationally targets generic help and promotional Bool/Claude content. This kind of scope deception can cause incorrect routing, unsafe activation in unrelated contexts, and bypass of user or platform expectations about what the skill is supposed to do.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The title presents a domain-specific planning tool, while the body describes unrelated generic promotional/help workflows. This contradiction increases the chance that operators, reviewers, or automated systems will misclassify the skill and invoke it in inappropriate contexts.

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
The documented behavior and trigger surface do not match the skill's stated purpose of USA business migration planning. This kind of semantic mismatch can cause the wrong skill to activate for unrelated requests, leading to prompt hijacking of user intent, unsafe routing, and accidental handling of promotional or account-circumvention content under a misleading business-focused label.

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The supposed 'validated requirement' is actually a promotional post rather than a clearly defined user need. Basing skill behavior on spam-like or irrelevant source material increases the chance the agent will operationalize low-quality, deceptive, or policy-evasive workflows instead of solving a legitimate task.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger sentence uses broad natural language such as 'Help me...' tied to a long, messy request fragment, which can cause unintended invocation during ordinary conversation. Overbroad activation increases the chance that the skill runs without clear user intent, potentially exposing users to irrelevant or policy-violating behavior hidden behind the skill.

Vague Triggers

Medium
Confidence
85% confidence
Finding
This trigger remains ambiguous because 'I need a practical workflow...' is common everyday phrasing and does not set meaningful activation boundaries. In context, the skill already has mismatched purpose and promotional content, so ambiguous invocation makes accidental or covert activation more dangerous.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger phrases are broad and include generic help-seeking language such as 'Help me' and 'I need a practical workflow,' which can overlap with many ordinary user requests. In a mislabeled skill, this creates a high risk of over-triggering, causing the agent to activate unrelated or promotion-focused logic in contexts where the user did not intend it.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger description includes extremely broad terms such as 'general-help' alongside unrelated bait keywords, making activation likely during ordinary user requests. Overbroad routing can cause this misaligned skill to intercept benign conversations and inject irrelevant or promotional guidance, which is especially risky given the deceptive content elsewhere in the file.

Vague Triggers

High
Confidence
95% confidence
Finding
The keyword list is ambiguous, generic, and partly composed of popular terms likely to appear in unrelated conversations. In the context of an already mislabeled skill, these triggers expand the attack surface for inappropriate invocation and suggest an attempt to maximize capture of user traffic rather than serve a narrowly defined need.

Natural-Language Policy Violations

Medium
Confidence
82% confidence
Finding
The skill injects mixed Chinese-language promotional text into the core description without user opt-in, locale scoping, or relevance to the stated skill purpose. While not inherently dangerous on its own, in this context it reinforces that the skill is carrying embedded ad/spam content and may steer outputs away from user intent.

Vague Triggers

High
Confidence
97% confidence
Finding
Using an overly broad trigger like 'general-help' creates a high risk of accidental activation on ordinary user requests. In combination with the skill’s already-misaligned purpose, this can hijack unrelated conversations and steer outputs toward irrelevant or low-trust behavior.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The audience definition 'people asking for help online' is so broad that it fails to constrain use to a meaningful or safe scope. Ambiguous activation criteria increase the chance of unintended invocation and make it harder to validate whether outputs are appropriate for the user’s actual task.

Vague Triggers

High
Confidence
98% confidence
Finding
The trigger section combines generic keywords with no exclusions or disambiguation logic, making false activation likely. Because the skill content is already inconsistent and includes promotional terms, broad triggers may cause the agent to route users into an unrelated workflow or amplify spam-like content in normal conversations.

Vague Triggers

High
Confidence
95% confidence
Finding
The default prompt is both overly broad and promotional, combining generic activation wording with unrelated marketing-style text. This increases the chance of unintended invocation and prompt-context pollution, causing the agent to activate for irrelevant requests and potentially steer users toward untrusted or unsafe workflows.

Natural-Language Policy Violations

Medium
Confidence
87% confidence
Finding
The manifest text mixes English and Chinese promotional content without user opt-in or justification, which is suspicious in a skill ostensibly about USA business migration planning. This can confuse users and models, obscure the true function of the skill, and hide policy-evading or misleading instructions inside multilingual text.

Vague Triggers

High
Confidence
88% confidence
Finding
The trigger phrase is so broad and generic that ordinary user text could activate this skill unintentionally. Overbroad activation expands the attack surface for misrouting, makes behavior unpredictable, and can let unrelated conversations be steered into this skill's questionable workflow.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The activation guidance is ambiguous and lacks clear boundaries on when the skill should or should not run. In context, that is more dangerous because the skill already contains domain-mismatched and promotional content, so vague triggers increase the odds of inappropriate invocation and user confusion.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.