Back to skill

Security audit

Work Productivity Skill Vetter Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with broad activation wording, but it does not show hidden execution, data access, persistence, or destructive behavior.

Installers should be aware that this skill may activate more often than intended because it lists generic trigger terms and allows implicit invocation. Consider narrowing activation wording before publishing or installing, but the reviewed artifact itself is not destructive or deceptive.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger guidance includes very broad, everyday phrasing that could cause the skill to activate in contexts far beyond its intended purpose. In an agent environment, this can lead to accidental invocation during unrelated conversations, causing inappropriate workflow insertion, confusing outputs, or unintended handling of security-related requests.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The invocation guidance is underspecified and overly broad, making it unclear when the skill should versus should not be used. This increases the risk of misrouting user requests to this skill, especially because terms like 'security', 'first', 'before', and 'github' are common across many unrelated tasks and could cause inappropriate activation.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger keywords and example invocations are broad enough to match generic requests such as 'security', 'first', 'github', or 'bug fix', which can cause the skill to activate outside its intended scope. In an agent ecosystem, accidental invocation can route unrelated user tasks through this workflow, creating confusion, unsafe automation decisions, or overshadowing more appropriate skills.

Vague Triggers

High
Confidence
96% confidence
Finding
The skill description is broad enough to match many ordinary requests such as 'security', 'first', or general workflow help, which can cause the skill to activate outside its intended domain. Over-broad activation increases the chance of unintended prompt injection surface, incorrect tool routing, and user confusion because the skill may intercept requests better handled by more specific or safer skills.

Vague Triggers

High
Confidence
98% confidence
Finding
The keyword list includes vague, high-frequency terms like 'security', 'first', 'before', and 'github' that appear in many unrelated conversations. This makes accidental invocation highly likely and can let the skill influence tasks far outside its intended purpose, expanding exposure to adversarial content and creating unsafe or misleading workflow selection.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The example trigger sentences are vague and tautological, showing invocation based on broad language rather than clear activation boundaries. This reinforces ambiguous matching behavior and trains integrators or downstream systems to treat loosely related requests as sufficient to invoke the skill, increasing misrouting and overreach.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger keywords are overly broad and include generic terms like "security", "first", "before", and "github", which can cause the skill to activate during ordinary conversation unrelated to this skill’s intended purpose. In an agent environment, this increases the chance of unintended routing, context hijacking, or the skill influencing tasks it was not meant to handle, which can degrade safety and reliability.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The activation description is broad and ambiguous, stating the skill should be used for a wide range of requests involving productivity, security, checklists, analysis, or implementation support. This can cause the skill to be selected in contexts beyond its intended scope, leading to over-activation and possibly unsafe or low-quality assistance when a more specialized skill should be used instead.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The default prompt contains a very broad activation phrase and generic terms like 'help me' plus common productivity/security wording, which increases the chance of accidental or implicit invocation in normal user conversations. Because implicit invocation is enabled, this can cause the skill to trigger when the user did not explicitly intend it, potentially injecting workflow behavior or instructions into unrelated tasks.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentences and keyword list are broad enough to match generic terms like 'security', 'first', 'github', and 'before', which can cause the skill to activate in unrelated conversations. Unintended activation is dangerous because it can route users into the wrong workflow, override more appropriate skills, and create confused-deputy behavior in security-sensitive contexts where precise tool selection matters.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.