Back to skill

Security audit

Work Productivity Skill Vetter Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly documentation-only, but its automatic invocation scope is too broad for a security/vetting helper and could steer unrelated user requests.

Review this skill carefully before installing. Its content is not executable and does not ask for secrets, but it may activate automatically in ordinary conversations about security, GitHub, installation, or bug fixes. Prefer installing only if you are comfortable with that broad routing, or revise the triggers to require explicit Skill Vetter-related wording.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger sentence is written as a natural-language phrase that overlaps with ordinary user requests, which can cause the skill to activate when the user did not explicitly intend to invoke it. In a security- and vetting-related skill, unintended activation is more dangerous because it can steer analysis workflows, inject irrelevant guidance, or cause the agent to apply this skill in contexts where different safety constraints should govern.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The invocation guidance relies on generic phrasing such as 'I need a practical workflow' and similar common language, without clear boundaries distinguishing normal conversation from intentional skill use. Because this skill is positioned around vetting, security, and bug-fixing workflows, accidental invocation could cause the agent to prioritize this skill over others and alter decision-making in sensitive analysis contexts.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrases are broad and include common terms like "security," "first," "before," "installing," and "github," which can cause the skill to activate in many unrelated conversations. In an agent environment, overbroad activation can route user requests into the wrong workflow, creating misleading security guidance, unintended task execution paths, or prompt-surface expansion that attackers may abuse through trigger stuffing.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger keywords are extremely broad, including common terms like "security," "first," "before," and "github," which can cause the skill to activate in many unrelated conversations. Over-broad activation increases the chance that the skill's workflow will inappropriately influence unrelated tasks, creating prompt-scope confusion and weakening user control over when the skill is invoked.

Vague Triggers

High
Confidence
95% confidence
Finding
The description says to use the skill when a user asks for broad categories like "security," "work-productivity," or any practical workflow or checklist, which creates an overly expansive invocation scope. This can cause the skill to be selected for requests outside its intended domain, leading to misapplication of instructions and increased risk of prompt interference across unrelated tasks.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The example trigger phrases model vague, catch-all activation language instead of demonstrating precise situations where the skill should be used. Because examples often shape routing behavior and author expectations, these broad examples reinforce accidental invocation and make the activation boundary even less predictable.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger list includes very broad, common terms such as "security", "first", "before", and "github", which can cause this skill to activate in many unrelated conversations. Over-broad activation is dangerous because it can route users into an unintended workflow, increasing the chance of irrelevant guidance, prompt hijacking surface, or accidental execution of a security-oriented skill in the wrong context.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The default prompt uses very broad natural-language trigger terms such as 'help me' combined with generic work and security-related phrasing, which can overlap with ordinary user requests. This increases the chance of unintended or implicit invocation, especially because implicit invocation is enabled, causing the skill to activate in contexts the user did not specifically intend.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger phrases are broad enough to match common, unrelated user requests such as generic 'security', 'github', 'first', or 'bug fix' queries. This can cause the skill to activate outside its intended scope, potentially injecting workflow guidance or authority into conversations where it was not explicitly requested, increasing the risk of misrouting, unintended privilege of this skill over safer alternatives, or user confusion in security-sensitive contexts.

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.