Back to skill

Security audit

Work Productivity Nano Banana Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

The skill is a plain workflow helper, but its automatic activation terms are broad enough to affect unrelated requests.

Before installing, consider narrowing the trigger keywords or disabling implicit invocation so the skill only runs for explicit Nano Banana Pro-style workflow requests, not generic image editing, generation, or bug-fix tasks.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrases are extremely generic and include common terms like "nano," "banana," "pro," "generate," "edit," and "bug fix," which can cause the skill to activate for many unrelated requests. In an agent environment, unintended invocation can route user tasks into the wrong workflow, producing irrelevant outputs or bypassing more appropriate, safer, or narrower skills.

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger phrases are broad enough to match ordinary requests like 'generate', 'edit', 'images', or generic workflow help, which can cause the skill to activate outside its intended scope. In an agent ecosystem, overbroad routing can misapply prompts or workflows to unrelated tasks, increasing the risk of unintended actions, confusion, or unsafe delegation.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger keywords include extremely generic terms such as "nano," "banana," "pro," "generate," "edit," and "bug fix," which are likely to match many unrelated requests. This can cause the skill to activate outside its intended scope, leading to incorrect routing, unintended influence over unrelated tasks, and reduced trust in skill selection.

Vague Triggers

High
Confidence
95% confidence
Finding
The manifest description says to use the skill when a user asks for broad terms like "work-productivity," "nano," "banana," or "pro," which creates an excessively ambiguous activation condition. Because descriptions are often used for routing or discovery, this broad matching can cause over-invocation and cross-domain interference with unrelated user intents.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The example trigger sentences are vague and repetitive, and they do not show distinguishing conditions or cases where the skill should not activate. This increases the chance that implementers or routing systems will infer a much broader activation surface than intended, compounding the ambiguity already present in the manifest and keyword list.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger list includes extremely broad everyday terms such as "nano", "banana", "pro", "generate", "edit", and "images", which can cause the skill to activate in many unrelated conversations. Overbroad activation increases the chance the agent injects irrelevant workflow guidance into unrelated tasks, causing prompt-routing errors, unintended behavior, and possible interference with safer or more appropriate skills.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The description says to use the skill when the user mentions broad terms or needs general artifacts, checklists, analysis, or implementation support for the requirement, but it does not clearly define exclusion criteria or scope limits. This ambiguity can lead to accidental invocation outside the intended context, reducing predictability and potentially exposing users to irrelevant or conflicting instructions.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill enables implicit invocation while providing no narrow activation guardrails, so it can be selected for loosely related user requests without explicit consent. In this context, the skill is framed around broad productivity and workflow help, which increases the chance of unintended triggering and prompt-scope overreach rather than containing it to a precise domain.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The default prompt uses very broad everyday-language terms such as 'help me' and generic workflow/support phrasing, which can overlap with many unrelated user requests. Because the skill also permits implicit invocation, this broad language makes accidental or overbroad routing materially more likely, potentially causing the agent to apply the skill outside its intended context.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger sentences are broad, generic, and include common help-seeking phrasing that could activate this skill in contexts unrelated to the intended Nano Banana workflow requirement. That creates an overbroad routing surface where normal user requests may unintentionally invoke the skill, leading to prompt hijacking of task selection, irrelevant execution, or interference with safer or more appropriate skills.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The usage signals section lacks precise activation boundaries and mixes broad keywords like "generate", "edit", and "images" with ambiguous invocation phrasing. In a multi-skill environment, this can cause accidental or adversarial triggering by unrelated user prompts, increasing the chance of misrouting, unexpected behavior, or priority capture over more suitable skills.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.