Back to skill

Security audit

Work Productivity Skill Vetter Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-style workflow helper with overly broad activation wording, but it does not ask for hidden access, credentials, persistence, or destructive actions.

Install only if you want a general skill-vetting workflow helper. Expect possible accidental activation because the trigger terms are too generic; narrowing the triggers would improve reliability before broad use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are broad and include common terms like "security," "first," and "github," which can cause the skill to activate for many unrelated user requests. In an agent environment, unintended invocation can route sensitive or unrelated tasks into this workflow, increasing the chance of incorrect behavior, prompt hijacking exposure, or user confusion.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are broad enough to match common terms like 'security', 'github', 'first', and 'before', which can cause the skill to activate in unrelated conversations. In a security-oriented workflow helper, unintended invocation is risky because it may steer users into the wrong workflow, produce irrelevant guidance, or interfere with more appropriate skills during sensitive vetting tasks.

Vague Triggers

High
Confidence
96% confidence
Finding
The skill description says to use the skill when a user asks for very generic terms like "security" or "first," which are common across many unrelated requests. This can cause unintended activation and routing, letting the skill intercept broad classes of conversations and potentially override more appropriate, narrowly scoped skills.

Vague Triggers

High
Confidence
98% confidence
Finding
The keyword list includes ambiguous everyday terms such as "security," "first," "before," and "github," which are likely to appear in many benign prompts. Broad triggers increase the chance of accidental invocation, prompt shadowing, and misclassification of user intent, especially in multi-skill environments.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The example trigger phrases are malformed, incomplete, and do not clearly define when the skill should activate. Poorly constrained examples can encourage loose matching behavior and make the already broad scope harder to interpret safely, increasing accidental activation risk.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger list includes very common words such as "security", "first", "before", and "github", which can cause the skill to activate in many unrelated conversations. Unintended invocation can override more appropriate skills, inject irrelevant workflow guidance into unrelated tasks, and create opportunities for prompt-scope confusion in security-sensitive contexts.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The description says to use the skill for broad categories like work-productivity, security, and practical support artifacts, without clear boundaries. This ambiguity increases the chance of misrouting requests into this skill even when the user's intent is unrelated, which can reduce reliability and create unsafe context blending if the skill is invoked during sensitive security discussions.

Vague Triggers

High
Confidence
95% confidence
Finding
The default prompt embeds a long, generic trigger phrase containing common terms like "help me" and broad workflow/security language, which increases the chance of unintended invocation during normal user conversation. Because implicit invocation is enabled, this broad phrasing can cause the agent to route unrelated requests into this skill, creating prompt-routing confusion and potentially exposing users to actions or guidance they did not intend to request.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger examples are broad, generic phrases that overlap with normal user language, which can cause the skill to activate in unintended contexts. In a security- and workflow-oriented skill, accidental invocation can lead to irrelevant guidance, misrouting, or unnecessary trust in a vetting workflow when the user did not explicitly request it.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger scope is ambiguous because it mixes broad keywords like 'security', 'first', 'before', and 'github' with loosely structured trigger sentences, without clear gating conditions. This increases the chance of over-triggering on unrelated requests and can cause the agent to apply this skill outside its intended context, reducing reliability and potentially interfering with safer or more appropriate skills.

VirusTotal

51/51 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.