Back to skill

Security audit

Work Productivity Skill Vetter Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overly broad activation text, but no hidden execution, persistence, credential access, or data exfiltration behavior.

Install only if you want a general Skill Vetter-style workflow assistant. Be aware it may activate too broadly because terms like security, first, before, github, and bug fix are generic; narrowing triggers would improve routing precision.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger sentences are broad and partially generic, including terms like 'security', 'first', 'github', and vague workflow requests. In an agentic environment, this can cause unintended activation in unrelated contexts, leading the skill to intercept tasks it was not meant to handle and potentially influence security-sensitive workflows without clear user intent.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrases are broad and overlap with generic terms like 'security', 'first', 'github', and 'bug fix', which can cause the skill to activate in many unrelated contexts. In an agent ecosystem, unintended invocation can route user requests into the wrong workflow, leading to mis-scoped actions, incorrect guidance, or accidental processing of sensitive tasks under an unsuitable skill.

Vague Triggers

High
Confidence
97% confidence
Finding
The manifest description includes broad activation terms such as "security" and "first," which are common in many unrelated user requests. This can cause the skill to activate outside its intended scope, potentially intercepting requests better handled by other skills and steering users into an unintended workflow.

Vague Triggers

High
Confidence
98% confidence
Finding
The trigger keyword list contains vague everyday words including "security," "first," "before," and "github," which are extremely broad and likely to match many benign conversations. Overbroad triggers increase the chance of accidental invocation, prompt hijacking of unrelated tasks, and unsafe routing decisions in multi-skill environments.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example triggers are malformed, truncated, and do not clearly communicate when the skill should activate. Ambiguous examples weaken operator understanding and can lead to misconfiguration or overbroad matching behavior, especially when combined with already generic keywords.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger list includes very broad everyday terms such as "security", "first", "before", and "github", which can cause the skill to activate in many unrelated conversations. In an agent environment, overbroad activation can route user requests into the wrong workflow, causing unintended actions, misleading guidance, or security analysis where it was not requested.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The description says the skill should be used when users mention broad categories like work-productivity, security, or need a practical workflow, checklist, analysis, or implementation support, but it does not clearly bound the scope. This ambiguity increases the chance that the skill is selected for requests outside its intended domain, leading to incorrect assistance or workflow interference.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The default prompt and description are broad enough to match generic requests for productivity, security, analysis, checklists, and implementation help. This can cause the skill to be invoked in situations far beyond its intended scope, increasing the chance of prompt hijacking, unintended disclosure of skill behavior, or user confusion about why this skill was selected.

Vague Triggers

Medium
Confidence
95% confidence
Finding
Enabling implicit invocation without strict trigger constraints allows the platform to auto-select this skill for loosely related user requests. Because the skill is described in very general terms, this broad auto-invocation expands attack surface and can lead to unexpected execution in sensitive contexts where the user did not explicitly request this workflow.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentence starts with very common phrasing like 'Help me' and 'I need', which can cause the skill to activate during ordinary user requests that were not intended to invoke this workflow. In an agent environment, overly broad activation increases the chance of accidental routing, context pollution, and execution of the wrong workflow, especially for a security-themed skill that may be given privileged analysis tasks.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The invocation guidance lists broad keywords and ambiguous phrases without defining boundaries for when the skill should or should not be selected. This makes misrouting more likely, causing unrelated requests containing words like 'security', 'github', or 'before' to invoke the skill improperly and potentially displace a safer or more appropriate skill.

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.