Back to skill

Security audit

Work Productivity Skill Vetter Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

The skill does not show malware-like behavior, but its very broad implicit activation could make it run during unrelated security, GitHub, or bug-fix requests.

Install only if you are comfortable with this skill being considered for a wide range of workflow, security, GitHub, and bug-fix prompts. The author should narrow the trigger phrases and disable or tightly constrain implicit invocation before this is treated as a low-friction general-purpose helper.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are extremely broad and include generic terms like 'security', 'first', 'github', and vague workflow requests, which can cause the skill to activate for many unrelated user prompts. In an agent ecosystem, this increases the chance of incorrect routing, unintended invocation, and the application of this skill’s instructions in contexts the user did not actually request.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger keywords and example phrases are broad enough to match common security- and productivity-related requests, which can cause the skill to activate when the user did not specifically intend to use it. In an agent environment, unintended invocation can redirect workflows, produce irrelevant or risky actions, and increase the chance that a user is steered into this skill's behavior without clear consent.

Vague Triggers

High
Confidence
96% confidence
Finding
The skill description is broad enough to match many ordinary requests, especially because it includes generic security and workflow language rather than a tightly scoped capability boundary. This can cause unintended invocation of the skill in unrelated contexts, increasing the chance that users are steered into this workflow when they did not request it and expanding the attack surface for prompt or policy interference.

Vague Triggers

High
Confidence
98% confidence
Finding
The keyword list includes ambiguous everyday words such as "security," "first," "before," and "github," which are likely to appear in many unrelated prompts. Overbroad keywords can make the skill fire unexpectedly, causing incorrect routing and allowing a broadly scoped skill to insert itself into sensitive or unrelated conversations.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The example trigger sentences are malformed and do not clearly show what should or should not activate the skill, which makes matching behavior harder to reason about and easier to misconfigure. Poor trigger examples reinforce overbroad activation and reduce operator ability to validate that the skill only runs in intended scenarios.

Vague Triggers

High
Confidence
96% confidence
Finding
触发关键词包含“security”“first”“before”“github”等高度常见且跨场景的词,会让该技能在大量无关请求中被误触发。对一个会引导安全审查/工作流决策的技能而言,误触发会干扰用户原始任务、覆盖更合适的技能选择,并可能把用户带入不相关的安全或修复流程。

Vague Triggers

Medium
Confidence
90% confidence
Finding
技能描述中的启用条件写成“当用户提出 work-productivity, skill-vetter, vetter, security, first,或需要……支持时使用”,范围过宽且边界模糊,几乎可覆盖大量普通生产力或安全相关请求。这会造成路由歧义,使技能在并非针对该特定 job-to-be-done 的场景下被选中,影响系统行为可预测性和最小权限原则。

Vague Triggers

Medium
Confidence
88% confidence
Finding
The default prompt is broad and phrased like common user language, which increases the chance of unintended or implicit invocation. Because implicit invocation is enabled, normal requests containing generic productivity or security-related terms could trigger this skill unexpectedly, causing prompt/context injection into unrelated workflows and reducing user control.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentences and keywords are broad enough to match common requests about security, GitHub, bug fixes, or practical workflows, which can cause the skill to activate outside its intended scope. In an agent ecosystem, this increases the chance of misrouting user requests, unexpected instruction injection into unrelated tasks, and user confusion about why this skill was selected.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.