Back to skill

Security audit

Work Productivity Nano Banana Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overbroad activation wording but no evidence of unsafe actions, persistence, credential access, or hidden behavior.

Installers should be aware that this skill may be selected for unrelated requests because its triggers are too generic. It is otherwise a low-risk documentation workflow helper; narrowing the trigger phrases to explicit Nano Banana Pro workflow requests would improve reliability.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger sentence is extremely broad and can activate on ordinary user requests like 'Help me...' without strong constraints tying invocation to this specific skill. That increases the chance of unintended routing or over-activation, which can cause the agent to apply this workflow in contexts the user did not explicitly request.

Vague Triggers

High
Confidence
92% confidence
Finding
This trigger uses generic wording like 'I need a practical workflow,' which is common across many benign requests and does not clearly scope activation to the Nano Banana helper. Ambiguous triggers create prompt-routing risk, where the wrong skill may activate and influence outputs, possibly bypassing better-matched or safer workflows.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger keywords and example invocations are very broad, including generic terms like "nano", "pro", "generate", "edit", and "bug fix" that commonly appear in unrelated user requests. This can cause the skill to activate outside its intended scope, leading to unintended routing, user confusion, or execution of an irrelevant workflow in contexts where more specialized or safer handling was expected.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger list includes extremely broad terms such as "nano," "banana," "pro," "generate," and "edit," which are common in unrelated user requests. This can cause the skill to activate outside its intended scope, leading to prompt-routing confusion, unintended behavior, and increased exposure to any unsafe instructions or logic embedded in the skill.

Vague Triggers

High
Confidence
94% confidence
Finding
The manifest description says to use the skill when a user asks for broad terms like "practical workflow," "artifact," "checklist," "analysis," or "implementation support," which are common across many benign tasks. This ambiguous routing condition risks accidental invocation for unrelated requests, undermining isolation between skills and making unintended execution more likely.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger keyword list includes extremely generic terms such as "nano", "banana", "pro", "generate", "edit", and "images", which are likely to match many unrelated user requests. This can cause the skill to activate outside its intended scope, increasing the chance of incorrect routing, irrelevant behavior, or accidental interception of prompts better handled by other skills.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The description says to use the skill whenever users mention broad categories like work-productivity or need practical workflows, checklists, analysis, or implementation support for the requirement, but it does not clearly define exclusion criteria. This ambiguity can make orchestration unreliable by encouraging over-selection of the skill for requests only loosely related to the intended Nano Banana workflow use case.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example trigger phrases are generic restatements of the broad demand statement and do not constrain scope or illustrate edge cases. Without negative examples or precise examples, downstream systems and maintainers may treat a wide range of unrelated prompts as valid activations, leading to prompt-routing errors and degraded reliability.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The manifest enables implicit invocation with a very broad description and trigger phrasing, making it easy for the agent to auto-select this skill in loosely related contexts. This can cause unintended activation, prompt-scope expansion, and execution of workflow logic when the user did not clearly request this skill, increasing the chance of misuse or unsafe cross-context behavior.

Vague Triggers

High
Confidence
92% confidence
Finding
The trigger sentence begins with an extremely broad phrase ('Help me ...'), which can cause the skill to activate for many unrelated user requests. In an agent-routing context, overbroad triggers increase the chance of unintended invocation, irrelevant guidance, and prompt-surface expansion where unrelated conversations get steered into this skill unnecessarily.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger sentence is ambiguous and insufficiently scoped, so it does not clearly distinguish this skill from many other productivity or implementation requests. This can lead to accidental routing, user confusion, and inappropriate application of the skill in contexts where its assumptions, workflows, or outputs do not fit the user's real need.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.