Back to skill

Security audit

Work Productivity Nano Banana Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This skill is a documentation-style workflow helper, with no executable code or credential handling found, though its activation terms are overly broad.

This appears suitable if you want a lightweight workflow helper for Nano Banana Pro-style skill and image-workflow planning. Be aware that its current triggers are broad enough to activate for unrelated requests, so explicit invocation or tightened keywords would make installation cleaner.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger sentence is broad and natural-language-like, making it likely to match ordinary user requests that were not intended to invoke this skill. Accidental invocation can route unrelated tasks into this workflow, causing confusing behavior, wrong tool use, or unsafe delegation patterns if the skill takes action based on weak matches.

Vague Triggers

Medium
Confidence
96% confidence
Finding
This trigger remains ambiguous because it describes a generic need for a practical workflow rather than a precise condition for activation. In an agent ecosystem, ambiguous triggers increase the chance of unintended skill selection, which can override better-matched skills or expose users to actions and outputs they did not request.

Vague Triggers

Medium
Confidence
98% confidence
Finding
The keyword list contains very common terms such as 'nano', 'banana', 'pro', 'generate', 'edit', and 'images', which are too generic to safely drive skill activation. Overbroad keywords can cause frequent accidental triggering across unrelated conversations, increasing the risk of misrouting, incorrect automation, and unexpected access to skill behaviors.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger keywords and example phrases are broad, generic, and partially unrelated to a narrowly scoped skill, which can cause the skill to activate in unintended contexts. In an agent ecosystem, overly permissive activation can route unrelated user requests into this workflow, increasing the chance of incorrect task handling, prompt-scope confusion, or accidental invocation of downstream capabilities.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger list includes extremely generic terms like "nano," "banana," "pro," "generate," and "edit," which are common in unrelated user requests. This can cause the skill to activate outside its intended scope, leading to irrelevant guidance, prompt-routing errors, or unintended interception of requests better handled by other skills.

Vague Triggers

High
Confidence
94% confidence
Finding
The manifest description says to use the skill when a user asks for broad terms like "work-productivity," "nano," "banana," "pro," or any practical workflow/artifact/checklist support for the requirement. This ambiguous and expansive activation language increases the chance of accidental invocation across many unrelated conversations, which can degrade routing integrity and cause inappropriate skill selection.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger list includes very generic terms such as 'nano', 'banana', 'pro', 'generate', 'edit', and 'images', which can match many unrelated user requests. This can cause frequent unintended activation, leading the agent to apply irrelevant workflow instructions and potentially interfere with safer or more appropriate skills.

Vague Triggers

High
Confidence
95% confidence
Finding
The skill description says it should be used whenever a user asks for broad categories like work-productivity, practical workflows, checklists, analysis, or implementation support for the requirement. These boundaries are vague and expansive, making it difficult for the orchestrator to distinguish when this skill is truly applicable versus when another skill should handle the request.

Vague Triggers

High
Confidence
95% confidence
Finding
The default prompt contains broad, common-language trigger terms such as "help me" and generic productivity-related phrasing, which can cause the skill to be invoked in unrelated conversations. Because implicit invocation is enabled, this increases the chance of accidental routing to this skill, creating prompt-scope confusion and making it easier for a broadly matching skill to intercept user requests unintentionally.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger examples include extremely broad terms such as "nano," "banana," and "pro," which are common everyday words and product descriptors unrelated to the skill's intended scope. This can cause unintended activation for unrelated user requests, leading the agent to inject irrelevant workflow behavior or artifacts into conversations where it does not belong.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The invocation guidance and trigger sentences do not clearly bound when the skill should activate, and they mix broad productivity language with vague references to popular demand. In an agentic environment, ambiguous routing rules increase the chance of over-invocation, causing context confusion, inappropriate execution, or accidental handling of requests outside the skill's intended domain.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.