Back to skill

Security audit

Work Productivity Skill Vetter Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with no code execution, credential handling, persistence, or hidden data movement, but its activation wording is broader than ideal.

Install only if you want a general skill-vetting workflow helper. Be aware that its broad trigger words may cause it to appear for general security, GitHub, or bug-fix requests; explicit invocation is preferable until the triggers are narrowed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger sentences and keywords are broad enough to match many ordinary requests involving security, GitHub, bug fixing, or vetting, which can cause unintended skill activation. In an agent environment, accidental invocation can route users into the wrong workflow, leading to misleading guidance, wasted actions, or unexpected processing of user context.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger phrases are extremely broad and include common terms such as "security," "first," "github," and "bug fix," which can cause the skill to activate in many unrelated conversations. In an agent environment, unintended invocation can redirect user workflows, cause the wrong skill to process sensitive requests, and increase the chance of unsafe or confusing automation behavior.

Vague Triggers

High
Confidence
96% confidence
Finding
The skill description includes very broad trigger terms such as "security" and "first" that can match many ordinary user requests unrelated to this skill’s narrow purpose. Over-broad activation increases the chance the skill is invoked unexpectedly, causing prompt/context hijacking of unrelated tasks and reducing user control over which workflow governs the interaction.

Vague Triggers

High
Confidence
98% confidence
Finding
The keyword list contains ambiguous generic terms including "security," "first," "before," and "github," which are common across many benign conversations. In an agent ecosystem, such broad selectors can cause this skill to preempt more appropriate skills or inject unintended workflow instructions into unrelated sessions, creating a meaningful routing and policy-confusion risk.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example triggers are malformed, truncated, and do not clearly communicate the exact activation boundary for the skill. Poorly specified examples make accidental or inconsistent invocation more likely, which weakens predictability and can be exploited indirectly by crafting prompts that resemble these vague examples.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger list includes very broad, high-frequency terms such as "security", "first", "before", and "github", which can cause the skill to activate in many unrelated conversations. Over-broad activation can route users into the wrong workflow, causing unintended handling of prompts, confusion, and potentially unsafe automation behavior in contexts where this skill was not intended to run.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The description says to use the skill when a user asks for broad categories like work-productivity, security, or practical workflow support, which leaves activation boundaries unclear. Ambiguous scope increases the chance of accidental invocation and misclassification, especially because the skill is framed as generally useful across several roles and tasks.

Natural-Language Policy Violations

Medium
Confidence
79% confidence
Finding
This file is presented only in Chinese and does not indicate language negotiation or fallback behavior, which can lead to misunderstanding by users or systems expecting another language. In a security- or workflow-related skill, language mismatch can cause users to miss important assumptions, limitations, or safety guidance, making erroneous execution more likely.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill enables implicit invocation but does not define narrow trigger constraints, so it may activate in response to broad user requests without explicit user intent. In a security- and workflow-oriented skill, unexpected activation can cause over-collection of context, inappropriate guidance insertion, or prompt-surface expansion that increases the chance of misuse or confusion.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The default prompt uses broad, everyday-language phrasing such as 'help me' and generic productivity/security wording, which makes the skill eligible to match many unrelated requests. When combined with implicit invocation, this can cause unintended routing into the skill, leading to irrelevant or risky behavior and making it easier for prompt injection or task hijacking to influence the session.

Vague Triggers

High
Confidence
93% confidence
Finding
The invocation guidance does not define when the skill should not activate, so ambiguous requests may be captured without sufficient boundary checks. In an agent environment, missing exclusion criteria can lead to over-triggering, skill confusion, and unsafe delegation of tasks to a workflow that may not fit the user’s real intent.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The invocation guidance does not define when the skill should not activate, so ambiguous requests may be captured without sufficient boundary checks. In an agent environment, missing exclusion criteria can lead to over-triggering, skill confusion, and unsafe delegation of tasks to a workflow that may not fit the user’s real intent.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.