Back to skill

Security audit

Work Productivity Skill Vetter Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-style workflow helper with overly broad activation wording, but it does not include code, hidden execution, credential handling, persistence, or destructive behavior.

Before installing, be aware that this skill may activate for generic security, GitHub, bug-fix, or workflow requests. It is best treated as a low-risk advisory helper, but its trigger wording should be narrowed if you want predictable routing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrases are broad enough to match common terms like 'security', 'first', 'github', and generic requests for workflows or bug fixes, which can cause the skill to activate outside its intended scope. In an agent ecosystem, this increases the chance of unintended invocation, misrouting user tasks, and applying this skill in contexts where its guidance is irrelevant or less safe.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger keywords and example phrases are very broad, including generic terms like 'security', 'first', 'github', and 'bug fix'. This can cause the skill to activate for many unrelated requests, leading to unintended interception of user workflows, confused routing, and possible overreach into contexts where the skill's vetting behavior was not requested.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger list is excessively broad, including generic terms like "security," "first," "before," and "github," which can cause the skill to activate for many unrelated requests. In an agent environment, this increases the chance of unintended routing or tool invocation, which can interfere with user intent and potentially insert security-themed workflow guidance into contexts where it was not requested.

Vague Triggers

High
Confidence
94% confidence
Finding
The skill description uses ambiguous activation criteria such as "security," "first," and requests for any "practical workflow, artifact, checklist, analysis, or implementation support," which are broad enough to match many benign conversations. This creates a prompt-squatting style risk where the skill may be selected over more appropriate skills, causing misrouting, confusion, and potentially overbroad access to user workflows.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger list includes very generic terms such as "security", "first", "before", "github", and "bug fix", which are common in unrelated conversations. This makes accidental activation likely, causing the skill to run outside its intended scope and potentially override or interfere with more appropriate workflows, especially in security-sensitive contexts.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The invocation description says to use the skill for broad topics like work-productivity, security, or practical workflow support, but it does not clearly define where this skill should stop and other skills or general assistance should take over. That ambiguity increases the chance of unintended routing, which can mis-handle user requests or expose users to irrelevant or lower-quality guidance in sensitive vetting scenarios.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The default prompt is written as a very broad natural-language trigger containing common terms like 'help me' and generic workflow/security phrasing, which can cause unintended or implicit invocation during ordinary user requests. Because implicit invocation is enabled, this increases the chance that the skill activates without clear user intent, potentially injecting its behavior or prompt context into unrelated conversations.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger sentences are broad enough to match common requests containing generic terms like 'help me', 'practical workflow', 'security', or 'github', which can cause the skill to activate outside its intended scope. In an agent-routing context, this can misroute user tasks, override more appropriate skills, and increase exposure to unintended processing of unrelated requests.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.