Back to skill

Security audit

Work Productivity Nano Banana Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with no executable code, credential handling, persistence, or hidden data access, though its activation wording is broader than ideal.

Install only if you want a broad workflow helper for Nano Banana Pro-style skill and productivity workflows. Be aware it may activate on generic image-editing or workflow requests unless invocation rules are narrowed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger sentence begins with a very generic helper phrase ('Help me ...') that overlaps with ordinary user language and can cause the skill to activate unintentionally in unrelated conversations. Because this is a workflow/helper skill with broad work-productivity scope, accidental invocation is more likely and may redirect tasks, inject irrelevant instructions, or interfere with routing to more appropriate skills.

Vague Triggers

High
Confidence
96% confidence
Finding
The phrase 'I need a practical workflow for ...' is a broad, everyday request pattern that lacks strong scoping and could match many legitimate user prompts unrelated to this specific skill. In a skill intended for practical workflow, checklist, analysis, or implementation support, this broad matching surface increases the chance of unintended invocation and prompt-routing confusion.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger section includes very broad keywords such as "nano," "banana," "pro," "generate," and "edit," plus generic request templates that can match ordinary user language. This can cause unintended activation or routing of unrelated conversations into this skill, increasing the chance of incorrect actions, prompt hijacking surface, or unsafe workflow execution in contexts the user did not intend.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger list includes extremely generic terms such as 'nano', 'banana', 'pro', 'generate', 'edit', 'images', and 'bug fix', which are likely to match many unrelated user requests. This can cause the skill to activate outside its intended scope, leading to confused delegation, accidental handling of unrelated tasks, and increased exposure to any unsafe behavior or bad guidance contained in the skill.

Vague Triggers

High
Confidence
95% confidence
Finding
The manifest description is overly broad, saying to use the skill whenever a user needs a 'practical workflow, artifact, checklist, analysis, or implementation support,' alongside generic keywords. Such expansive invocation guidance makes the router more likely to select this skill for unrelated productivity requests, effectively over-scoping the skill and undermining least-privilege behavior in agent orchestration.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger keywords include very broad generic terms such as "nano", "banana", "pro", "generate", "edit", and "images", which can cause the skill to activate on many unrelated user requests. Over-broad activation increases the chance of inappropriate context injection, routing errors, and accidental execution of workflow guidance outside its intended scope.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The description says to use the skill when users mention broad terms or need practical workflow support, but it does not define clear boundaries or exclusions. This ambiguity can make the orchestrator invoke the skill for loosely related requests, causing misrouting and untrusted instructions to be surfaced in contexts where they do not belong.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The example trigger phrases are phrased as everyday help requests and practical workflow asks, which are common across many benign conversations. Because the examples are too general, they may train or bias the system toward activating this skill on ordinary support prompts, expanding exposure beyond intended scenarios.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The default prompt is framed as a generic trigger to use the skill for broad workflow help, without meaningful constraints on when invocation is appropriate. Combined with allow_implicit_invocation: true, this increases the chance the agent will auto-select the skill in contexts the user did not clearly intend, which can cause prompt-scope overreach, unsafe delegation, or unintended handling of sensitive work-productivity tasks.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger sentence includes broad, everyday phrasing such as 'Help me' and 'I need a practical workflow' tied to a long requirement description. This can cause the skill to activate for many unrelated user requests, leading to unintended invocation, confused routing, and possible overshadowing of more appropriate skills.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger section lacks scope boundaries and negative examples, so the router has little guidance on when this skill should not be used. In a broad work-productivity category with generic keywords like 'nano', 'pro', 'generate', and 'edit', this increases accidental matches and misroutes user requests into an only loosely related workflow.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.