Back to skill

Security audit

Work Productivity Skill Vetter Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This documentation-only workflow helper does not show hidden execution or data access, though its broad trigger words could make it activate in unrelated requests.

Before installing, consider narrowing the trigger wording or using explicit invocation so the skill is only used for skill-vetting workflow help, not generic security, GitHub, or bug-fix requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger sentences and keywords are overly broad, including generic terms like "security," "first," "before," and "github," which can cause the skill to activate in contexts unrelated to its intended purpose. In an agent environment, ambiguous activation increases the chance of misrouting user requests, unintended workflow execution, or an attacker deliberately invoking the skill when a narrower, safer tool should have handled the task.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger examples include very generic terms and phrases such as 'security', 'first', 'before', 'github', and broad natural-language prompts that could match many unrelated user requests. This can cause unintended activation of the skill, leading to workflow hijacking, user confusion, or insertion of this skill into contexts where its guidance is not appropriate, which is especially risky for a security/vetting-oriented skill that may influence trust decisions.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger list includes extremely broad terms like 'security', 'first', 'before', and 'github', which are common in unrelated conversations. This can cause the skill to activate outside its intended scope, creating prompt-routing confusion and increasing the chance that users receive this skill's workflow in inappropriate contexts.

Vague Triggers

High
Confidence
94% confidence
Finding
The manifest description says to use the skill when a user asks for broad concepts like 'security', 'first', or 'practical workflow', which are ambiguous and likely to match many unrelated requests. In a skill-selection system, this overbroad invocation condition can hijack routing and expose users to irrelevant or misleading guidance.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The example trigger sentences are vague, repetitive, and do not establish clear semantic boundaries for activation. Poor examples can reinforce overbroad matching behavior, making accidental invocation more likely and reducing operator ability to distinguish intended from unintended use.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger keywords include very broad everyday terms such as "security", "first", "before", and "github", which can cause this skill to activate in many unrelated conversations. Over-broad activation increases the chance that the wrong skill handles user input, leading to misrouting, irrelevant instructions, or unintended exposure of sensitive workflow context in security-related interactions.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill description covers a very wide set of actions—bug fixing, hardening, reliability improvement, adjacent skill creation, checklists, analysis, and implementation support—without clear boundaries for when this skill should or should not be selected. This ambiguity can make orchestration choose the skill in contexts beyond its competence, which is especially risky because the subject matter includes security and workflow vetting.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The default prompt uses broad natural-language activation text such as 'help me' and generic work/security-related terms, which can cause the skill to be invoked in situations the user did not clearly intend. Because implicit invocation is also enabled, this increases the chance of accidental routing to this skill, exposing users to unintended behavior, confusing outputs, or unsafe delegation in security-sensitive workflows.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrases are broad and generic enough to match many ordinary security, GitHub, bug-fix, or workflow requests that are not specifically about this skill. This can cause unintended activation and routing, making the agent apply the wrong workflow or expose users to irrelevant or risky automation in contexts where a more precise skill should have been selected.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.