Back to skill

Security audit

Work Productivity Nano Banana Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overly broad activation wording, but it does not contain hidden execution, persistence, credential handling, or data exfiltration behavior.

Before installing, be aware that this skill may activate too easily because its trigger terms are broad. It is best used when you explicitly want Nano Banana Pro-style workflow, reliability, bug-fix, or adjacent-skill planning help; otherwise it may add irrelevant workflow framing to unrelated requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger examples are broad and malformed enough that they could match ordinary user requests unrelated to this specific skill, causing unintended activation. In an agent ecosystem, accidental invocation can route user input into the wrong workflow, creating confusion, incorrect task execution, or unsafe chaining with other capabilities.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The activation guidance lacks clear boundaries and uses ambiguous, truncated examples, which increases the chance that the orchestration layer or users will invoke the skill in unintended contexts. Because this is a workflow-helper skill with broad productivity framing, ambiguous triggering makes misrouting more likely and can degrade reliability or lead to inappropriate outputs being generated under the wrong assumptions.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger keywords and example invocations are excessively generic (for example, 'pro', 'generate', 'edit', 'images', and 'bug fix'), which can cause this skill to activate for unrelated user requests. In an agent ecosystem, overbroad activation can route sensitive or unintended tasks into a workflow the user did not explicitly choose, increasing the risk of confused-deputy behavior, privacy mistakes, or unsafe task execution.

Missing User Warnings

Medium
Confidence
83% confidence
Finding
The README references image generation/editing and Gemini-related usage but does not warn users that requests or artifacts may involve external model handling, third-party services, or sensitive data exposure. This omission can lead users to provide confidential images, prompts, or work materials without understanding where data may go or what processing occurs.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger list includes highly generic terms such as "nano," "banana," "pro," "generate," "edit," and "images," which are common in many unrelated requests. This can cause the skill to activate outside its intended scope, leading to incorrect routing, unintended handling of user tasks, and possible overshadowing of more appropriate skills.

Vague Triggers

High
Confidence
93% confidence
Finding
The manifest description says to use the skill when a user asks for broad terms like "work-productivity," "nano," "banana," or "pro," and for generic needs like a "practical workflow, artifact, checklist, analysis, or implementation support." Such ambiguous activation language greatly expands the match surface and can make the skill trigger for many unrelated requests, reducing reliability and potentially steering users into the wrong workflow.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger list includes very broad, high-frequency terms such as "nano", "banana", "pro", "generate", "edit", and "images", which can cause the skill to activate in many unrelated conversations. This creates an unsafe routing condition where users may be steered into this workflow unexpectedly, increasing the chance of irrelevant instructions, confusion, or accidental invocation of workflow logic outside its intended scope.

Vague Triggers

High
Confidence
93% confidence
Finding
The skill description says it should be used when users ask for broad terms like work-productivity, nano, banana, or pro, or whenever they need a practical workflow, artifact, checklist, analysis, or implementation support for the requirement. This activation language is overly expansive and underspecified, making accidental matching likely and allowing the skill to claim a much wider set of requests than its niche purpose justifies.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The default prompt uses a very broad natural-language invocation phrase covering generic terms like 'help me' and common productivity-related wording. Combined with implicit invocation, this can cause the skill to trigger in ordinary conversations without clear user intent, increasing the chance of prompt hijacking, unintended routing, or accidental disclosure of context to this skill.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger sentence is overly broad and can activate on common user phrasing rather than a clearly scoped request for this specific skill. That creates an over-triggering/prompt-routing risk where unrelated conversations may invoke the skill unexpectedly, increasing the chance of irrelevant guidance, unintended workflow execution, or exposure of internal skill behavior in the wrong context.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger description uses ambiguous activation wording and lacks clear scope boundaries, so the skill may be selected for loosely related requests that merely resemble the topic. In an agent environment, ambiguous routing increases the attack surface for prompt/skill misuse by allowing adversarial or accidental phrasing to pull in this skill outside its intended context.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.