Back to skill

Security audit

Work Productivity Nano Banana Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a low-privilege workflow helper, but its broad trigger wording could make it activate for unrelated requests.

Use this skill only when you specifically want Nano Banana Pro workflow-planning help. Because implicit invocation is enabled and the keywords are broad, review agent routing behavior if you install it in an environment with many skills.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases are extremely broad, including generic terms like "nano," "banana," "pro," and common task language such as "generate" and "edit." In an agent-routing context, this can cause the skill to activate for unrelated requests, creating prompt-scope confusion and increasing the chance that users are steered into unintended workflows or that higher-risk instructions are applied in the wrong context.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger keywords and example invocations are overly broad, including generic terms like 'nano', 'pro', 'generate', 'edit', and 'bug fix'. This can cause unintended activation in unrelated conversations, increasing the chance the skill runs out of context and produces workflow guidance or artifacts the user did not request, which is a prompt-routing and authorization boundary problem rather than just a usability issue.

Vague Triggers

High
Confidence
98% confidence
Finding
The trigger keyword list is excessively broad and includes common words like 'nano', 'banana', 'pro', 'generate', 'edit', and 'bug fix'. In agent routing systems, this can cause the skill to activate for many unrelated requests, creating prompt-scope hijacking risk where users are steered into an irrelevant workflow or where this skill preempts more appropriate, safer, or more specialized skills.

Vague Triggers

High
Confidence
95% confidence
Finding
The skill description says to use the skill when a user asks for broad concepts like 'work-productivity', 'nano', 'banana', 'pro', or practical workflow support, without meaningful constraints. This creates an overbroad invocation boundary that can cause accidental or competing activation across many normal conversations, reducing routing integrity and increasing the chance that unrelated user tasks are handled under the wrong instructions.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The example trigger phrases are vague, truncated, and framed in generic task language such as 'Help me' and 'I need a practical workflow'. Such examples train routing behavior toward broad matching and reinforce accidental invocation patterns, especially when combined with the already-generic keyword list and description.

Vague Triggers

High
Confidence
98% confidence
Finding
The trigger keywords include extremely broad everyday terms such as "nano", "banana", "pro", "generate", "edit", and "images", which can match many unrelated user requests. This can cause the skill to activate outside its intended scope, leading to prompt hijacking of unrelated workflows, user confusion, and unintended execution of this skill’s instructions in benign contexts.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The top-level description defines the skill’s applicability very broadly, covering generic requests for practical workflows, artifacts, checklists, analysis, or implementation support whenever users mention common terms like work-productivity or pro. Because the scope is not bounded by explicit exclusions or precise activation criteria, the skill may be selected for many unrelated tasks, increasing the chance of unintended instruction injection into other contexts.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The manifest allows implicit invocation while describing the skill in very broad terms such as general workflow, checklist, analysis, and implementation support. This makes it easier for the agent platform to activate the skill in situations the user did not clearly intend, which can cause prompt-scope creep, unsafe delegation, or unintended handling of unrelated tasks.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger sentence is overly broad and includes generic phrasing such as 'Help me' and 'I need a practical workflow', which can cause the skill to activate in unrelated conversations. This creates prompt-routing risk: users may unintentionally invoke this skill, exposing them to irrelevant instructions or causing downstream actions based on the wrong workflow context.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The invocation guidance lacks precise boundaries and mixes broad keywords like 'nano', 'banana', and 'pro' with generic productivity language. In an agent ecosystem, that ambiguity increases accidental activation and misrouting, which can degrade reliability and potentially route sensitive user requests into an unintended skill path.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.