Back to skill

Security audit

Work Productivity Skill Vetter Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with no executable code, but its activation terms are too broad and could make it appear in unrelated conversations.

This skill appears safe to install from an execution-risk standpoint, but users should be aware that its broad triggers may cause it to activate for general security, GitHub, installation, or bug-fix requests where a more specific skill may be better.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger sentences and keywords are broad enough that this skill could activate in unrelated security- or GitHub-related conversations, causing workflow hijacking or unintended invocation. In a skill that positions itself as a vetting/security helper, accidental activation is more dangerous because it may steer sensitive review tasks, influence trust decisions, or override a more appropriate skill selection path.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger phrases are broad and include generic terms like security, first, github, and bug fix, which can cause the skill to activate for many unrelated requests. In an agent ecosystem, this increases the chance of unintended routing, where users seeking general help are silently steered into this workflow and may receive irrelevant or misleading guidance.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger keyword list is excessively broad, including generic terms like "security," "first," "before," and "github" that commonly appear in unrelated requests. This can cause unintended activation and routing of user prompts into this skill, increasing the chance of prompt hijacking, incorrect workflow execution, or interference with more appropriate skills.

Vague Triggers

High
Confidence
95% confidence
Finding
The manifest description uses broad activation language such as "Use when a user asks for work-productivity, skill-vetter, vetter, security, first" which effectively turns common user vocabulary into activation criteria. In a multi-skill environment, this ambiguity can cause over-selection of the skill and misapplication of its instructions to unrelated tasks.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The example trigger phrases are vague and nearly content-free, repeating truncated demand text rather than showing bounded, realistic user intents. Poorly scoped examples encourage permissive matching behavior and make it harder for orchestrators or maintainers to distinguish valid invocation cases from ordinary conversation.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger list includes very broad everyday terms such as "security", "first", "before", and "github", which can cause the skill to activate in many unrelated conversations. Overbroad activation increases the chance that this workflow intercepts requests outside its intended scope, leading to user confusion, unsafe context switching, or unintended influence over sensitive security-related tasks.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The description says the skill should be used when users mention broad terms like work-productivity, vetter, security, or first, or whenever they need a practical workflow or checklist. This creates unclear activation boundaries and may cause the skill to engage for unrelated requests, which is especially risky because it presents itself as security- and vetting-oriented and may steer decision-making in the wrong context.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The default prompt embeds a long, generic natural-language trigger phrase including common terms like 'help me' and broad workflow/security wording, which can cause unintended or overly frequent invocation. In a skill that offers security and workflow assistance, accidental activation can misroute user intent, inject irrelevant instructions into conversations, and increase the chance that the skill influences tasks where it was not explicitly requested.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger sentences include broad, ordinary terms such as "help me," "practical workflow," and "security," which can match many unrelated user requests and cause the skill to activate outside its intended scope. In an agent environment, overbroad activation can route sensitive or irrelevant tasks into this skill unexpectedly, increasing the chance of incorrect handling, prompt interference, or unsafe downstream actions.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger specification does not define clear activation boundaries or negative examples, so the agent may be unable to distinguish intended use from general productivity or security discussions. This ambiguity increases accidental invocation risk and can degrade reliability, especially because the skill markets itself around broad workflow and analysis support.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.