Back to skill

Security audit

Work Productivity Skill Vetter Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overly broad activation wording, but it shows no hidden execution, credential use, persistence, or data movement.

This skill appears safe to install from a security perspective, but users should be aware it may activate too easily on ordinary requests involving security, GitHub, or bug fixes. Prefer explicit invocation or tighten the trigger terms before relying on it in workflows where precise skill routing matters.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger sentence is broad and natural-language-like enough that ordinary user requests about fixing bugs or hardening workflows could unintentionally activate the skill. This can cause the agent to invoke the wrong skill in security-sensitive contexts, leading to misrouting, unexpected behavior, or accidental application of this workflow when the user did not explicitly request it.

Vague Triggers

Medium
Confidence
90% confidence
Finding
This activation text describes use in ambiguous terms and includes generic workflow language that overlaps with many normal requests. In a skill related to vetting and security, ambiguous invocation is more dangerous because it may intercept unrelated analysis requests and influence outcomes in contexts where precision and user intent are important.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrase examples are broad, natural-language prompts that overlap with ordinary requests for help, making accidental or unintended invocation more likely. In a security- or vetting-related skill, overbroad activation can cause the agent to route unrelated conversations into this workflow, leading to incorrect handling, user confusion, and possible bypass of safer or more appropriate skills.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The invocation guidance does not define precise boundaries for when the skill should activate, and the keyword list includes very common terms like 'security', 'first', 'github', and 'bug fix'. This makes the skill prone to overmatching many unrelated user requests, which is especially risky for a workflow helper that may influence analysis or operational decisions in contexts where a more specialized skill should be used.

Vague Triggers

High
Confidence
95% confidence
Finding
The skill description is broad enough to match many ordinary requests, especially because it includes generic terms like 'security', 'artifact', 'analysis', and 'implementation support' without clear boundaries. This can cause the skill to activate outside its intended niche, potentially hijacking unrelated conversations and influencing agent behavior in contexts where its workflow is not appropriate.

Vague Triggers

High
Confidence
98% confidence
Finding
The keyword list includes vague, high-frequency terms such as 'security', 'first', 'before', and 'github', which are common in many benign user requests. In a skill-routing system, these terms can cause accidental invocation at large scale, leading to prompt-scope overreach, misrouting, or unintended precedence over more relevant skills.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The example trigger sentences are malformed and do not clearly indicate the intended boundary for activation, which increases ambiguity for implementers and may encourage loose matching. Ambiguous examples reinforce overbroad routing behavior and make it harder to distinguish legitimate invocations from unrelated requests.

Vague Triggers

High
Confidence
94% confidence
Finding
触发关键词包含“security”“first”“before”“github”等高频且语义宽泛的词,会让技能在大量无关对话中被误触发。误触发后,该技能可能在并不需要该工作流的场景中插入流程化建议或安全评审内容,造成上下文偏移、结果污染,甚至覆盖更合适的专用技能。

Vague Triggers

High
Confidence
91% confidence
Finding
描述中写明当用户提出“work-productivity, skill-vetter, vetter, security, first”时即可使用,其中既有非常宽泛的主题词,也缺少明确边界与优先级。这会扩大技能的适用面到大量普通请求,导致代理错误选择该技能,降低路由准确性并放大误操作风险。

Vague Triggers

Medium
Confidence
92% confidence
Finding
The default prompt contains a very broad natural-language trigger phrase and the policy allows implicit invocation, increasing the chance the skill is activated during ordinary user requests that merely mention related terms. In a security- and workflow-oriented skill, unintended invocation can cause confusing behavior, prompt hijacking opportunities, or the accidental application of this skill in contexts where the user did not explicitly request it.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrases are broad, everyday-language prompts like 'help me' and 'I need a practical workflow' combined with generic terms such as security, bug fix, and github. This can cause the skill to activate outside its intended scope, leading to accidental invocation in unrelated contexts and increasing the chance that users receive misleading or over-privileged workflow guidance when another skill or safer default behavior should apply.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.