Back to skill

Security audit

Work Productivity Skill Vetter Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with no executable code or persistence, though its activation triggers are overly broad and users should invoke it intentionally.

Install only if you want a general Skill Vetter-style workflow helper. Because the trigger wording is broad, prefer explicit invocation by skill name and review generated plans before allowing any code or setup changes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are generic and partially match common user requests such as 'security', 'first', 'github', or broad workflow-help language, which increases the chance the skill will activate outside its intended scope. In an agent environment, unintended invocation can cause the wrong workflow to run, leading to irrelevant actions, confusion, or unsafe handling of sensitive setup/security tasks under incorrect assumptions.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are broad enough to match common words such as 'security', 'first', 'before', 'github', and 'bug fix', which can cause the skill to activate in contexts far beyond its intended scope. In a security-oriented vetting workflow, unintended activation can misroute user requests, override more appropriate skills, or inject workflow behavior into unrelated tasks, reducing reliability and potentially affecting security-sensitive decision flows.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger keywords are extremely broad, including generic terms like "security," "first," "before," and "github," which can cause the skill to activate during ordinary conversation unrelated to this skill’s intended purpose. Over-broad activation increases the chance of accidental routing, context hijacking, or inappropriate use of this skill in situations where a more specific or safer skill should respond.

Vague Triggers

High
Confidence
91% confidence
Finding
The description says to use the skill when a user asks for broad concepts like "security," "first," or any practical workflow or analysis support, which creates an ambiguous invocation boundary. This can lead to unintentional activation across many unrelated requests, increasing the risk of misrouting user tasks and giving this skill authority beyond its intended scope.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The example trigger sentences are malformed and overly vague, so they do not provide reliable activation guidance and may encourage fuzzy matching. Poorly specified examples make accidental invocation more likely and reduce operator confidence in when the skill should or should not run.

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger keywords are overly broad and include common terms such as "security", "first", "before", and "github", which can match many unrelated user requests. This can cause accidental invocation of the skill in contexts where its workflow is not intended, leading to confused behavior, incorrect routing, or unneeded exposure of the skill’s instructions and outputs.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The skill description says to use the skill when a user asks for broad categories like work-productivity, security, or practical workflow support, but it does not define clear boundaries for when the skill should or should not activate. Ambiguous invocation criteria increase the chance of misrouting unrelated requests into this skill, reducing predictability and potentially interfering with safer or more appropriate skills.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The default prompt contains very broad trigger terms such as 'work-productivity', 'security', 'first', and generic workflow language, which can match ordinary user requests and cause unintended invocation. Because implicit invocation is enabled, this increases the chance the skill activates in unrelated conversations, potentially injecting unneeded instructions or influencing security-sensitive tasks without clear user intent.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger sentences and keyword list are overly broad and include generic terms like "security," "first," "before," and "github," which can cause the skill to activate in many unrelated conversations. This creates scope-hijacking risk: the agent may invoke this workflow helper when the user did not intend it, potentially displacing safer or more appropriate skills and causing incorrect handling of security-sensitive tasks.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.