Back to skill

Security audit

Work Productivity Skill Vetter Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This skill is a documentation-style workflow helper with no executable code, credential access, persistence, or hidden data movement, though its activation wording is overly broad.

Installers should expect a low-risk workflow helper, but should narrow or disable implicit invocation before publishing widely so ordinary requests mentioning security, GitHub, or bug fixes do not accidentally trigger this skill.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are broad, generic, and overlap with common terms like 'security', 'first', 'github', and 'before', which can cause the skill to activate outside its intended context. In an agent environment, overbroad activation can route unrelated or sensitive user requests into the wrong workflow, leading to incorrect guidance, prompt hijacking surface expansion, or unsafe automation decisions.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are broad, generic, and overlap with common security and productivity terms such as "security", "first", "github", and "bug fix", which can cause the skill to activate in unrelated contexts. In an agent ecosystem, unintended invocation can route user requests through the wrong workflow, causing misleading vetting outputs, unnecessary privilege use, or accidental execution of a security-oriented process on benign tasks.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger keywords are overly broad, including generic terms like 'security', 'first', and 'github', which can cause the skill to activate for many unrelated requests. In an agent environment, this increases the chance of incorrect routing, unintended skill invocation, and unsafe overreach into tasks outside the skill's validated scope.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The description instructs use for broad and loosely defined intents such as 'needs a practical workflow, artifact, checklist, analysis, or implementation support,' which is expansive enough to capture many unrelated requests. This ambiguity can lead an orchestrator or user to apply the skill beyond its intended domain, reducing reliability and potentially causing unsafe or misleading assistance.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The example trigger sentences are malformed, truncated, and not specific enough to demonstrate safe activation conditions. Poor trigger examples can cause confusion in implementation or training, making accidental invocation more likely and weakening the skill's routing precision.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger keywords are overly broad and include common terms such as “security”, “first”, “before”, and “github”, which can match many unrelated user requests. This can cause the skill to activate unexpectedly, leading to misrouting, confusing responses, and accidental invocation of a security-themed workflow in contexts where it was not intended.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The description defines activation using a vague mix of broad categories and generic terms, without clearly distinguishing this skill from other productivity or security helpers. Ambiguous activation conditions increase the chance of accidental selection, especially in systems that rely on keyword or semantic matching to route user requests.

Natural-Language Policy Violations

Medium
Confidence
82% confidence
Finding
This file is written as a Chinese-localized skill definition but does not tell the system or user how language selection should occur, nor whether non-Chinese users should receive another variant. In multilingual environments, that can cause incorrect routing, reduced user comprehension, and operational mistakes if a user receives instructions in an unexpected language.

Vague Triggers

High
Confidence
93% confidence
Finding
The default prompt contains a very broad natural-language trigger phrase including generic terms like 'help me' and a long descriptive sentence, which can overlap with ordinary user requests and cause unintended invocation of this skill. Because the skill is security- and workflow-oriented, accidental activation could steer conversations unexpectedly, inject unwanted workflow behavior, or cause the agent to privilege this skill in unrelated contexts.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger sentences contain very broad natural-language phrases such as requests for a 'practical workflow' or generic help wording, which can cause the skill to activate in many unrelated conversations. Overly permissive invocation increases the chance of accidental routing, confusing users, and inserting this skill into contexts where its security-analysis framing may be inappropriate or misleading.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.