Back to skill

Security audit

Work Productivity Nano Banana Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a low-authority workflow guidance skill with overly broad activation wording, but no executable code, credential handling, persistence, or hidden behavior.

Installers should understand that this skill may be selected too often because its trigger terms are generic and implicit invocation is enabled. Prefer invoking it by its full skill name when you specifically want Nano Banana Pro-style workflow help; otherwise the artifact does not show hidden execution, credential use, persistence, or destructive behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger examples use broad, natural-language phrases that could match many ordinary user requests unrelated to the skill’s intended scope. This increases the chance of accidental invocation or prompt routing collisions, which can cause the wrong skill to activate and produce unintended behavior or unsafe outputs in downstream workflows.

Vague Triggers

Medium
Confidence
97% confidence
Finding
The invocation guidance lacks specificity and boundaries, combining generic terms like 'help me' and 'I need a practical workflow' with a long requirement description. In agent ecosystems, this can lead to over-triggering, ambiguous routing, and unintended execution of a skill in contexts where it was not requested, reducing reliability and potentially bypassing user intent.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger keywords and example phrases are extremely broad, including generic terms like 'nano', 'banana', 'pro', 'generate', and 'images', which are likely to appear in unrelated user conversations. This can cause accidental skill invocation or routing collisions, leading the agent to apply the wrong workflow or expose users to unintended behavior without explicit consent.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger list is overly broad and includes generic terms like "nano," "banana," "pro," "generate," and "edit," which are likely to appear in many unrelated prompts. This can cause unintended skill activation, routing user requests into the wrong workflow and potentially exposing users to irrelevant or unsafe task handling when they did not intend to invoke this skill.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The description says to use the skill when a user asks for broad terms like "work-productivity," "nano," "banana," or "pro," which creates an ambiguous activation boundary. In practice, this increases the chance of accidental invocation on unrelated requests, leading to misrouting, confused task execution, and reduced trust in agent behavior.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger list includes extremely broad generic terms such as "nano", "banana", "pro", "generate", "edit", and "images", which are common in unrelated user requests. This can cause the skill to activate outside its intended scope, leading to unintended instruction injection into unrelated workflows and reducing user/control predictability.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The activation condition in the description is vague, saying the skill should be used when users mention broad categories or need general artifacts, analysis, or implementation support. This ambiguity increases accidental invocation risk and may route unrelated tasks into this skill, weakening least-surprise and separation-of-concerns.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The default prompt includes very broad natural-language trigger terms like 'help me' plus common productivity wording, which can cause the skill to be invoked during ordinary user requests that were not intended for this agent. In a system with implicit or prompt-based routing, this increases the chance of accidental activation, context hijacking, and unintended exposure of user data or workflow influence.

Vague Triggers

Medium
Confidence
97% confidence
Finding
Enabling implicit invocation without clear activation constraints allows the platform to auto-select this skill based on vague matches, which is risky when the skill description targets broad workplace productivity tasks. This can lead to over-invocation, interference with unrelated tasks, and unnecessary access to user context or execution pathways the user did not explicitly request.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger sentence is so broad and conversational that it can match many ordinary user requests unrelated to this skill’s intended scope. That increases the chance of accidental invocation, causing the agent to apply the wrong workflow, leak irrelevant guidance into conversations, or override more appropriate skills.

Vague Triggers

Medium
Confidence
89% confidence
Finding
A vague generic request pattern makes routing ambiguous and can cause this skill to activate for a wide range of loosely related tasks. In an agent environment, this creates prompt-selection risk, where the model may follow an irrelevant or lower-safety workflow instead of the best-matched skill.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.