Back to skill

Security audit

Work Productivity Nano Banana Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-style workflow helper with no executable code or credential handling, though its activation terms are too broad and may trigger unintentionally.

Before installing, be aware that this skill may be selected for ordinary requests involving image generation, editing, Gemini, or bug fixes. It appears safe as a workflow helper, but users who prefer precise routing should narrow the triggers or disable implicit invocation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

High
Confidence
92% confidence
Finding
The trigger sentence is extremely broad and resembles ordinary user language, which can cause the skill to activate unintentionally during unrelated requests. In an agent ecosystem, overbroad activation can redirect workflows, inject irrelevant instructions, and increase the chance that this skill interferes with tasks the user did not intend to route here.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger description lacks clear activation boundaries and mixes generic productivity terms with partial natural-language prompts, making accidental invocation more likely. Because this is a workflow helper intended for broad work-productivity scenarios, ambiguous routing is more dangerous here: the skill may be selected for many loosely related tasks and influence outputs without strong user intent.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger keywords and example invocations are broad enough to match generic terms like 'work-productivity', 'nano', 'banana', 'pro', 'generate', and 'bug fix', which can cause accidental or excessive activation of the skill outside its intended scope. In an agent ecosystem, ambiguous routing can lead to the wrong workflow being selected, producing unintended actions or irrelevant outputs and weakening safety boundaries between specialized skills.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger list includes extremely common terms like "nano," "banana," "pro," "generate," "edit," and "images," which can cause the skill to activate for unrelated user requests. Over-broad invocation increases the chance that this skill intercepts prompts outside its intended scope, leading to confused task routing, unsafe delegation, or unintended use of workflow guidance in contexts the user did not request.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The example trigger sentences use vague, reusable phrasing like "Help me" and "I need a practical workflow," which resembles normal conversation and can encourage accidental activation patterns. In combination with the broad keyword list, these examples normalize loose matching behavior and make unintended invocation more likely.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger list includes extremely generic terms such as "nano", "banana", "pro", "generate", "edit", and "images", which are likely to appear in many unrelated user requests. This can cause unintended invocation of the skill, leading the agent to apply the wrong workflow, override better-matched skills, or introduce irrelevant instructions into normal conversations.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The metadata description says to use the skill whenever a user asks for broad terms like work-productivity, nano, banana, or practical workflow support, which makes the activation scope ambiguous and overly expansive. In a multi-skill environment, this increases the chance of misrouting user requests and unintentionally injecting this skill's guidance into unrelated tasks.

Vague Triggers

High
Confidence
95% confidence
Finding
The default prompt contains highly generic trigger terms such as 'help me' and broad productivity-related wording, which can overlap with normal user requests. In combination with skill routing, this raises the chance of unintended activation, causing the agent to invoke this skill when the user did not explicitly intend to use it.

Vague Triggers

High
Confidence
97% confidence
Finding
Enabling implicit invocation without tightly constrained activation criteria allows the platform to auto-select this skill based on vague similarity rather than explicit user intent. Because the skill is framed around broad workflow, checklist, analysis, and implementation support, accidental invocation is more dangerous here than in a narrowly scoped skill and can lead to prompt hijacking of unrelated conversations or over-collection of context.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentence is extremely broad and resembles ordinary user language, which can cause the skill to activate in unrelated conversations. Over-broad activation increases the chance of unintended execution, prompt interference, and misrouting users into this workflow when they did not explicitly request it.

Vague Triggers

Medium
Confidence
92% confidence
Finding
This trigger remains ambiguous because it frames activation around a generic request for a 'practical workflow' without clear boundaries on when the skill should be used. Ambiguous routing can lead to accidental invocation across many normal productivity requests, reducing predictability and potentially exposing users to irrelevant or unsafe workflow guidance.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.