Back to skill

Security audit

Work Productivity Skill Vetter Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This skill is a low-capability workflow helper, but its implicit invocation and very broad trigger terms could cause it to run in unrelated security, GitHub, or bug-fix conversations.

Review this before installing if your agent auto-loads skills. The main risk is accidental activation in ordinary security, GitHub, installation, or bug-fix work; prefer explicit invocation or narrow the trigger keywords before use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (13)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger sentence begins with a very generic help-request pattern ('Help me ...'), which creates ambiguous activation boundaries and increases the chance the skill is invoked unintentionally. In a security- and vetting-related skill, accidental invocation can misroute user intent, interfere with other skills, or cause the agent to apply this workflow in contexts the user did not explicitly request.

Vague Triggers

Medium
Confidence
94% confidence
Finding
This trigger uses a common generic request form ('I need a practical workflow ...') without a strong boundary indicating when the skill should activate. Because the skill is positioned around security and vetting workflows, ambiguous invocation can cause inappropriate activation in unrelated conversations, leading to confusing behavior and potentially unsafe over-application of security guidance.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are broad enough to match ordinary user requests such as asking for help with security, GitHub, or bug fixes, which can cause the skill to activate outside its intended scope. In an agent ecosystem, overbroad activation increases the chance of unintended workflow execution, confusing routing, or inappropriate application of this skill to unrelated tasks.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The invocation guidance does not clearly define when the skill should and should not be used, so generic terms like 'security', 'first', or 'github' may cause ambiguous or accidental activation. This is particularly risky for a productivity/security-oriented skill because mistaken invocation can redirect sensitive analysis workflows or produce misleading outputs in the wrong context.

Vague Triggers

High
Confidence
95% confidence
Finding
The skill description includes extremely broad trigger terms such as 'security' and 'first', which can match many unrelated prompts and cause the skill to activate outside its intended scope. Over-broad routing is dangerous because it can hijack normal user requests, inject irrelevant workflow behavior into security-sensitive contexts, and reduce user control over which skill is invoked.

Vague Triggers

High
Confidence
97% confidence
Finding
The keyword list contains vague, high-frequency words like 'security', 'first', 'before', and 'github' without qualifiers, making accidental invocation very likely. In an agent ecosystem, this can cause prompt-routing confusion and unintended tool behavior, especially when users discuss common topics that have nothing to do with this specific workflow helper.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The example trigger sentences are vague, unnatural, and do not clearly show the boundaries for legitimate invocation, which reinforces loose matching behavior. Poor examples increase the chance that implementers or orchestrators will treat partial, generic phrasing as sufficient to load the skill, expanding its reach beyond intended use.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger keywords are overly broad, including common terms like 'security', 'first', 'before', and 'github'. This can cause the skill to activate in many unrelated contexts, leading to unintended interception of user requests and misrouting to this workflow, which is especially risky because the skill presents itself as security/vetting related and may influence sensitive decisions.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The description says the skill should be used for broad categories like work-productivity, security, and practical workflows without defining clear boundaries. Ambiguous enablement conditions increase the chance that the orchestrator invokes the skill for tasks outside its intended scope, producing irrelevant or misleading guidance.

Natural-Language Policy Violations

Medium
Confidence
76% confidence
Finding
The file is entirely in Simplified Chinese and does not indicate language-selection behavior or fallback handling. In multilingual environments this can cause misunderstanding of instructions, incorrect use of the skill, or silent misconfiguration when users or maintainers expect another language.

Vague Triggers

High
Confidence
94% confidence
Finding
The default prompt embeds very broad trigger terms such as 'work-productivity', 'security', 'first', and generic requests for practical help, which can overlap with ordinary user language. In combination with implicit invocation, this can cause the skill to activate unintentionally and inject its behavior or instructions into unrelated conversations, creating prompt-scope confusion and increasing the chance of unsafe or undesired actions.

Vague Triggers

High
Confidence
97% confidence
Finding
Enabling allow_implicit_invocation without strict activation constraints allows the skill to be invoked based on ambiguous context rather than clear user choice. Because this skill is framed broadly around workflows, security, checklists, and implementation help, accidental invocation could expose users to unwanted prompt injection, incorrect task routing, or security-relevant guidance being applied in the wrong context.

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger sentences are broad enough to match ordinary requests containing generic terms like 'security', 'github', 'bug fix', or 'workflow', which can cause the skill to activate outside its intended scope. Overbroad activation increases the chance that users are routed into this skill unexpectedly, leading to inappropriate handling, prompt-context collisions, or accidental invocation of workflows that were not requested.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.