Back to skill

Security audit

Work Productivity Nano Banana Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overbroad activation wording, but it does not request hidden access, persistence, credential use, or unsafe execution.

Installers should be aware that this skill may activate for generic words like 'pro' or 'edit'. It is otherwise a low-risk documentation workflow helper; consider narrowing triggers before broad deployment to reduce accidental invocation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger sentences and keywords are so broad that the skill may activate for loosely related prompts such as generic requests containing common words like "work," "nano," "banana," or "pro." This can cause unintended routing, making the agent apply this skill in the wrong context and potentially override safer or more appropriate workflows, reducing reliability and increasing the chance of unsafe task handling.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrases are broad, natural-language prompts that can match ordinary user requests unrelated to this specific skill. That increases the chance of unintended activation, causing the agent to apply the wrong workflow or expose users to behavior they did not explicitly request. In this context, the skill targets general productivity and workflow help, which makes broad activation especially risky because many everyday requests could overlap.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The keyword list includes highly generic terms such as 'nano', 'banana', 'pro', 'generate', 'edit', and 'images', which are too unspecific to safely define activation scope. These terms can collide with many unrelated conversations, leading to accidental skill routing and potentially incorrect or unexpected agent behavior. Because this skill presents itself as a practical workflow helper, overbroad keywords enlarge its reach beyond the intended niche and reduce operator control.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger list is overly broad and includes generic terms like "nano," "banana," "pro," "generate," "edit," and "bug fix," which can match many unrelated user requests. This creates a real risk of unintended skill activation, causing the wrong workflow to run and potentially steering users into irrelevant or unsafe guidance without clear intent.

Vague Triggers

High
Confidence
94% confidence
Finding
The manifest description says to use the skill when a user asks for broad terms like "work-productivity," "nano," "banana," or "pro," which is ambiguous and likely to overmatch normal conversation. Because descriptions often influence routing and operator expectations, this can cause the skill to be selected in contexts far outside its intended scope.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger keywords are excessively broad, including generic terms like "nano", "banana", "pro", "generate", and "edit" that commonly appear in unrelated requests. This can cause unintended activation of the skill for irrelevant tasks, leading to prompt routing errors, confusion, or the skill influencing workflows outside its intended scope.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The description defines activation conditions using a very wide set of topics and loosely bounded phrases like practical workflow, artifact, checklist, analysis, or implementation support. Because these categories are generic, the skill may be invoked in many unrelated contexts, increasing the risk of incorrect tool selection and unintended behavior.

Natural-Language Policy Violations

Medium
Confidence
76% confidence
Finding
The skill is provided only in a Chinese-language file without any visible locale negotiation or user language selection mechanism. In mixed-language environments, this can cause the skill to activate or respond in an unexpected language, reducing reliability and potentially causing users to misunderstand instructions or outputs.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The default prompt includes very broad trigger terms such as "help me" and generic workflow language, which can cause the skill to activate in many ordinary conversations unrelated to the intended niche use case. Because implicit invocation is enabled, this increases the chance of accidental routing, prompt hijacking opportunities, or unintended influence over user interactions.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger list includes highly generic tokens such as "nano", "banana", and "pro", which are common in unrelated everyday requests. This can cause the skill to activate outside its intended scope, leading to incorrect routing, unexpected behavior, or accidental invocation of workflows the user did not request.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.