Back to skill

Security audit

Work Productivity Nano Banana Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a passive workflow-helper skill with no executable code or sensitive access, though its broad implicit triggers may cause accidental activation.

Installers should be aware that this skill may be invoked for unrelated image, editing, or productivity prompts because its trigger language is broad. Prefer explicit invocation or narrow the trigger terms before enabling implicit routing in a multi-skill environment.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger sentence is phrased as a broad natural-language request pattern that can match ordinary user prompts unrelated to this specific skill. Overly generic invocation text increases the chance of accidental activation, causing the agent to apply the wrong workflow, inject irrelevant instructions, or override a more appropriate skill in mixed-skill environments.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The invocation conditions and keyword list are ambiguous and very broad, including common terms like 'nano', 'banana', 'pro', 'generate', 'edit', and 'images' that can appear in many unrelated requests. In an agent routing system, this can lead to unintended skill selection, prompt-scope confusion, and unreliable behavior when the skill activates outside its intended context.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrases include extremely generic terms such as "nano", "pro", "generate", "edit", and "images", which are likely to match many unrelated user requests. This can cause unintended skill activation, routing users into the wrong workflow, and potentially exposing them to misleading outputs or inappropriate automation paths without clear user intent.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger list is overly broad and includes generic words like "nano," "banana," "pro," "generate," "edit," and "bug fix," which can cause the skill to activate for many unrelated user requests. In an agent environment, this can lead to unintended routing, prompt shadowing, and the skill influencing tasks outside its intended scope.

Vague Triggers

High
Confidence
94% confidence
Finding
The manifest description says to use the skill whenever a user asks for broad terms like "work-productivity," "nano," "banana," or "pro," or whenever they need a generic artifact or checklist. This ambiguous guidance substantially widens the activation surface and can cause the skill to intercept unrelated requests, creating misrouting and unintended behavior across the agent system.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The example trigger sentences are generic and reusable across many unrelated skills, so they do not meaningfully constrain when this skill should be selected. Weak examples reinforce overbroad matching behavior and make accidental or excessive invocation more likely in automated routing systems.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger keyword list includes extremely generic terms such as "nano", "banana", "pro", "generate", "edit", and "images", which are likely to appear in unrelated conversations. This can cause the skill to activate outside its intended scope, leading to prompt hijacking of benign tasks, user confusion, or unintended routing into a workflow the user did not request.

Vague Triggers

High
Confidence
92% confidence
Finding
The skill description says it should be used whenever the user mentions broad terms or needs practical workflow/artifact/checklist/analysis/implementation support for the requirement, but it does not define clear boundaries for when it should not apply. That ambiguity increases the chance that orchestration systems or maintainers will invoke it for loosely related requests, creating overreach and unsafe task capture.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The example trigger phrases are broad and truncated, and they do not demonstrate meaningful constraints or counterexamples. Without negative examples, integrators may generalize the activation pattern too widely, increasing false positives and making the skill more likely to intercept unrelated user requests.

Vague Triggers

High
Confidence
98% confidence
Finding
The manifest allows implicit invocation while using a very broad default prompt and generic trigger terms like 'work-productivity', 'workflow', 'analysis', and 'implementation support'. This can cause the skill to be auto-selected in unrelated contexts, creating prompt-routing confusion and increasing the chance that sensitive user requests or higher-risk tasks are handled by the wrong skill without explicit user intent.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger set includes extremely broad terms like "nano," "banana," and "pro," which are common in unrelated user requests. This can cause the skill to activate outside its intended scope, leading to prompt/context hijacking of normal conversations and unintended execution of this workflow in irrelevant tasks.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.