Back to skill

Security audit

Work Productivity Nano Banana Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with no executable code, but its activation wording is too broad and may cause unwanted use in unrelated tasks.

Before installing, be aware that this skill may activate too easily for generic image, editing, bug-fix, or productivity requests. It is safest when invoked explicitly by name or when the task clearly concerns Nano Banana Pro-style workflow support.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger sentences are broad, repetitive, and include generic terms like 'nano', 'pro', 'generate', and 'bug fix', which can cause the skill to activate for loosely related requests. In an agent environment, this increases the chance of unintended invocation, context hijacking, or the skill influencing tasks outside its intended scope, reducing predictability and safety.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrase is broad enough to match ordinary requests using generic terms like 'help me' and 'practical workflow', which can cause the skill to activate outside its intended domain. In an agent ecosystem, overbroad activation can lead to prompt hijacking of unrelated tasks, unexpected workflow execution, and user confusion about why this skill was selected.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The activation guidance does not clearly define boundaries for when the skill should and should not activate, making routing decisions ambiguous. That ambiguity increases the chance that the skill is invoked for unrelated requests, which can degrade reliability and potentially expose users to unintended instructions or outputs from a mismatched workflow.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger list includes very generic terms like "nano," "banana," "pro," "generate," "edit," and "images," which can cause the skill to activate for many unrelated requests. Over-broad activation increases the chance this skill intercepts tasks outside its intended scope, leading to misrouting, unintended instruction precedence, or unsafe reliance on irrelevant workflow guidance.

Vague Triggers

High
Confidence
89% confidence
Finding
The manifest description says to use the skill when a user asks for broad themes like "work-productivity" or needs a "practical workflow, artifact, checklist, analysis, or implementation support," which is ambiguous and expansive. This weak scoping can cause the skill to be selected for many unrelated tasks, increasing prompt-routing errors and potentially exposing users to irrelevant or less-safe guidance in contexts the skill was not designed to handle.

Vague Triggers

High
Confidence
92% confidence
Finding
The trigger keywords include extremely broad everyday terms such as "nano", "banana", and especially "pro", which can match many unrelated user requests. This can cause the skill to activate outside its intended scope, increasing the chance of inappropriate routing, unintended prompt injection exposure from irrelevant contexts, or interference with other skills.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The activation condition in the description is broad and lacks clear boundaries or exclusions, so the orchestrator may invoke the skill for loosely related productivity or implementation requests. In a multi-skill environment, ambiguous routing increases misfires and can expose users to irrelevant instructions or cause the wrong skill to handle sensitive workflows.

Vague Triggers

Medium
Confidence
80% confidence
Finding
The example trigger phrases are vague and truncated, so they do not clearly distinguish valid invocations from ordinary conversation. Poor examples reinforce overbroad matching and make accidental activation more likely during prompt routing or by future maintainers copying the pattern.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill enables implicit invocation while using a broad, generic default prompt describing general workflow help, bug fixing, hardening, analysis, and implementation support. This creates an overbroad trigger surface where ordinary user requests may silently activate the skill, causing unintended routing, prompt injection exposure through skill content, or unexpected access to this skill's instructions in contexts where the user did not explicitly request it.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger phrases are broad and include common terms like 'work-productivity', 'nano', 'banana', and 'pro', which can cause the skill to activate for unrelated user requests. This creates unintended routing and prompt-injection exposure because an irrelevant conversation could invoke this skill and let its instructions influence the agent when the user did not actually request this workflow.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.