Back to skill

Security audit

Work Productivity Nano Banana Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overly broad activation wording, but no hidden code, credential access, persistence, or destructive behavior.

Installers should be aware that the skill may activate for unrelated requests because its triggers are broad and implicit invocation is enabled. Narrowing triggers to explicit Nano Banana Pro workflow requests would reduce confusion before publishing widely.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger keywords and example invocations are very broad, including generic terms like 'nano', 'banana', 'pro', 'generate', 'edit', and 'bug fix'. This increases the likelihood that unrelated user requests will accidentally invoke the skill, causing unintended context capture or inappropriate workflow execution in situations where the user did not intend to use this capability.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are broad, generic, and include common words like 'nano', 'banana', 'pro', 'generate', and 'edit', which can cause unintended activation outside the intended workflow context. In an agent environment, overbroad activation can route unrelated user requests into this skill, increasing the chance of incorrect task handling, prompt-scope confusion, or accidental execution of an unsafe or irrelevant workflow.

Vague Triggers

High
Confidence
98% confidence
Finding
The trigger list includes extremely generic terms such as "nano," "banana," "pro," "generate," and "edit," which are common in unrelated user requests. This can cause the skill to activate outside its intended scope, leading to prompt hijacking of unrelated tasks, user confusion, and unsafe delegation to a mismatched workflow.

Vague Triggers

High
Confidence
95% confidence
Finding
The description says to use the skill whenever a user asks for broad categories like work-productivity or any practical workflow, artifact, checklist, analysis, or implementation support. This creates an activation surface so broad that the skill can intercept many unrelated conversations, increasing the chance of incorrect tool selection and security boundary erosion.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The example trigger sentences use generic request framing like "Help me" and "I need a practical workflow" without clarifying what uniquely qualifies the request for this skill. These examples reinforce overbroad routing behavior and make accidental activation more likely in normal user interactions.

Vague Triggers

High
Confidence
95% confidence
Finding
触发关键词包含 `nano`、`banana`、`pro`、`generate`、`edit`、`images` 等高频通用词,会让技能在大量无关场景下被误触发。误触发会扩大该技能的上下文注入面,使其在并非预期的任务中介入并影响代理行为、输出质量或安全决策。

Vague Triggers

Medium
Confidence
89% confidence
Finding
技能描述中的适用条件覆盖 `work-productivity`、`nano`、`banana`、`pro` 及“practical workflow/artifact/checklist/analysis/implementation support”等宽泛需求,缺少清晰边界。这样的激活策略容易让调度器将普通生产力、图像或实现类请求错误路由到该技能,造成越权介入或不相关指令污染。

Vague Triggers

Medium
Confidence
86% confidence
Finding
示例触发句基本是对需求描述的截断复述,未展示真实边界条件,也没有反例说明,因此无法帮助调用方理解何时应该或不应该启用该技能。这会延续宽泛触发问题,增加误调用和不稳定编排的概率。

Vague Triggers

Medium
Confidence
94% confidence
Finding
The default prompt and skill description use very broad, everyday phrasing such as 'help me' and generic workflow terms, which can cause the platform to invoke this skill in situations far beyond its intended scope. Because implicit invocation is enabled, this ambiguity increases the chance of over-triggering, unintended context capture, and the skill influencing unrelated user tasks.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger examples include extremely broad terms such as "nano," "banana," and "pro," which are common everyday or generic words unrelated to a narrowly scoped skill invocation. This can cause accidental activation in unrelated conversations, leading the agent to apply the wrong workflow, introduce irrelevant instructions, or override user intent unexpectedly.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The invocation guidance is both underspecified and malformed: the trigger sentences are truncated and do not clearly define when the skill should or should not activate. Ambiguous or broken trigger guidance increases the chance of unintended invocation, misrouting of tasks, and unreliable agent behavior, especially in automated skill-selection systems.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.