Back to skill

Security audit

Work Productivity Nano Banana Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper, but its automatic activation terms are too broad and users should watch for accidental invocation.

This skill appears safe to install as a workflow aid, but its trigger words are broad enough that it may activate for unrelated requests. Prefer explicit invocation by skill name, and consider narrowing or disabling implicit invocation before publication.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger keywords and example trigger sentences are so generic that they can activate on ordinary conversation unrelated to the skill, causing unintended routing or invocation. In an agent ecosystem, this can lead to prompt/context hijacking at the orchestration layer, where the wrong skill gains access to user requests or influences execution unexpectedly.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are broad, generic, and include common terms like 'nano', 'banana', 'pro', 'generate', 'edit', and 'bug fix', which can cause the skill to activate for unrelated user requests. This increases the chance of unintended routing or prompt hijacking at the orchestration layer, especially because the skill is positioned as a general workflow helper rather than a narrowly scoped tool.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger list includes extremely common terms like "nano," "banana," "pro," and "generate," which are likely to match unrelated user requests and cause accidental activation. Over-broad activation can route benign conversations into this skill unexpectedly, creating confused-deputy behavior, irrelevant guidance, and possible interference with safer or more appropriate skills.

Vague Triggers

High
Confidence
90% confidence
Finding
The description says to use the skill when a user asks for broad categories like "work-productivity" or needs a "practical workflow, artifact, checklist, analysis, or implementation support," which lacks meaningful boundaries. This ambiguity increases the chance the skill will be selected for many unrelated requests, potentially overriding better-matched skills and expanding the skill's authority beyond its intended domain.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger keywords are overly broad and include generic terms like "nano", "banana", "pro", "generate", and "edit", which can match many unrelated user requests. This can cause accidental skill activation, leading the agent to apply irrelevant instructions or workflows in contexts where the user did not intend to invoke this skill.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The description says to use the skill when users mention broad terms or need general workflow, artifact, checklist, analysis, or implementation help for the requirement, but it does not clearly define exclusions or activation thresholds. This ambiguity increases the chance that the skill is invoked inappropriately, which can interfere with normal routing and cause the agent to prioritize the wrong behavior.

Vague Triggers

High
Confidence
96% confidence
Finding
The skill enables implicit invocation while providing only a broad, generic description of when it should run. This creates a substantial risk that the platform will auto-select the skill for ordinary productivity requests, causing untrusted prompt content from the skill to be injected into unrelated conversations without clear user intent.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The default prompt uses broad everyday phrasing such as 'help me' and general workflow/productivity language that overlaps heavily with normal user requests. This increases the chance of accidental activation or overbroad routing, which can inject the skill's instructions into sessions where the user did not specifically request this skill.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger configuration includes extremely generic terms such as "nano," "banana," and "pro," plus broad lead-ins like "I need a practical workflow," which are common in unrelated user requests. This can cause the skill to activate outside its intended scope, creating prompt-routing confusion and increasing the chance that users receive irrelevant or unsafe guidance from the wrong skill.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.