Back to skill

Security audit

Word Docx Formatting Repair Helper

Security checks across malware telemetry and agentic risk

Overview

This skill is a low-risk document-formatting helper, though its trigger wording is broad enough that it may activate for some unrelated productivity requests.

Installers should expect this skill to help with Word/DOCX-style formatting workflows and review outputs before applying any suggested script or document change. Because implicit invocation is enabled and the triggers are broad, users who want tighter behavior should invoke it explicitly for document-formatting tasks or narrow the trigger phrases before publishing broadly.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger sentences are generic and loosely scoped, which can cause the skill to activate for unrelated user requests. In an agent environment, over-broad activation increases the chance of misrouting tasks, applying the wrong workflow, or exposing users to unintended instructions when they did not explicitly request this skill.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill description is broad enough to match many ordinary productivity requests, which can cause the agent to invoke this skill outside its intended boundaries. Over-broad routing increases the chance of context confusion, inappropriate tool use, or accidental interception of requests that should be handled by a narrower or safer skill.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger keywords are generic terms like 'styles', 'automation', and 'find replace' that frequently appear in unrelated user requests. This makes unintended activation likely, which can lead to incorrect task routing and the model applying document-repair guidance where it does not belong.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example trigger sentences use vague, natural phrasing that overlaps with common everyday help requests, increasing collision with unrelated prompts. In a routing system, examples strongly influence matching behavior, so ambiguous examples can expand the skill's effective scope beyond safe intent.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill description is broad enough to match many common productivity and document-editing requests, which can cause the agent to invoke this skill in situations beyond its intended scope. Over-broad routing can lead to incorrect tool selection, unexpected handling of user data, or suppression of more appropriate skills, even though the content itself is not overtly malicious.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The listed trigger keywords are generic terms like work-productivity, styles, and automation that overlap with many unrelated tasks. This increases the chance of unintended invocation, causing the assistant to apply this skill where it is not relevant and potentially produce misleading outputs or interfere with safer, better-scoped skills.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The default prompt uses a highly generic trigger phrase tied to broad workplace tasks like document formatting and practical help, which can overlap with ordinary user requests and cause unintended implicit invocation. Because implicit invocation is enabled, this increases the chance the skill activates outside narrowly intended contexts, potentially inserting untrusted instructions or altering agent behavior when users did not explicitly request this skill.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger sentences are extremely broad and can match ordinary user requests about editing, formatting, or workflow help, causing the skill to activate outside a narrowly intended scope. Over-broad activation can hijack routing, inject irrelevant instructions into unrelated conversations, and increase exposure to prompt-surface attacks because the skill is invoked more often than necessary.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.