Back to skill

Security audit

Work Productivity Nano Banana Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-style workflow helper with overly broad activation wording, but it does not request dangerous access or perform hidden actions.

Before installing, be aware that this skill may activate on unrelated requests because its triggers include common words. It appears safe as a workflow helper, but the publisher should narrow the triggers and implicit invocation criteria to avoid confusing or irrelevant responses.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are very broad and include generic terms like 'nano', 'banana', 'pro', and common request shapes such as 'I need a practical workflow', which can cause unintended skill activation outside the intended context. In an agent environment, overbroad activation can route unrelated user tasks into this skill, leading to inappropriate instructions, workflow confusion, or unsafe handling of requests the skill was not designed for.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrases are broad and include generic terms like "nano", "pro", "generate", "edit", and "bug fix", which can cause accidental activation during unrelated conversations. In an agent ecosystem, unintended invocation can route user requests into the wrong workflow, causing incorrect actions, confusion, or policy bypass through mis-scoped skill selection.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger keywords are excessively broad, including generic terms like "nano," "banana," "pro," and "generate," which can cause this skill to activate for many unrelated user requests. In an agent environment, overbroad routing is dangerous because it can hijack normal tasks, suppress more appropriate skills, and increase the chance that users receive irrelevant or misleading workflow guidance.

Vague Triggers

High
Confidence
94% confidence
Finding
The manifest description defines invocation conditions using broad, everyday language like "practical workflow," "artifact," "checklist," and "analysis," which applies to a large share of ordinary requests. This creates an unsafe routing surface where the skill may be selected outside its intended scope, leading to prompt overreach and unintended influence over unrelated tasks.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The example trigger sentences are framed as generic help requests and do not provide meaningful separation from normal user queries. This reinforces the broad matching behavior and makes accidental invocation more likely, especially in systems that learn or rank triggers from embedded examples.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger keywords include very broad generic terms such as 'nano', 'banana', 'pro', 'generate', 'edit', and 'images', which can cause the skill to activate in many unrelated conversations. In an agent environment, over-broad activation can divert tasks to the wrong skill, leading to inappropriate instructions, user confusion, or unsafe workflow substitutions.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The description says the skill should be used when users mention broad terms or need practical workflow or implementation support, but it does not clearly define boundaries for when this skill should not apply. That ambiguity increases the chance of accidental routing to this skill, especially because the subject matter overlaps with generic productivity and implementation requests.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example trigger phrases are vague and largely repeat the broad demand statement rather than showing concrete, bounded activation conditions. Poor examples fail to constrain matching behavior and can reinforce over-triggering in systems that rely on examples for routing or prompt-based selection.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The default prompt contains very broad activation language tied to common terms like 'help me' and generic workflow concepts, which increases the chance the skill is invoked during ordinary user requests that were not meant to call this specific skill. In combination with the skill's broad productivity scope, this can cause unintended routing, prompt injection surface expansion, or accidental disclosure of skill behavior in unrelated conversations.

Vague Triggers

Medium
Confidence
95% confidence
Finding
Enabling implicit invocation without strict activation constraints allows the platform to call the skill based on loosely matching user language, which is risky for a broadly described helper skill. Because the skill is framed around common workplace tasks and generic artifacts like checklists, analysis, and implementation support, ordinary requests may unintentionally trigger it, increasing the likelihood of misrouting and unsafe skill invocation.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger sentence is overly broad and begins with a generic phrase ('Help me'), which can cause the skill to activate for many unrelated user requests. In an agent environment, this increases the risk of misrouting prompts and unintentionally invoking this skill in contexts where its workflow or assumptions do not apply.

Vague Triggers

Medium
Confidence
91% confidence
Finding
This trigger sentence is ambiguous and insufficiently scoped, so the router may match loosely related requests without clear user intent. That can lead to incorrect skill selection, irrelevant outputs, and potential leakage of context into an unintended workflow, especially when the skill advertises broad artifact and implementation support.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.