Back to skill

Security audit

Work Productivity Skill Vetter Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overly broad activation wording, but it does not request credentials, hidden execution, persistence, or privileged access.

Installers should be aware that this skill may activate more often than intended because its trigger wording is broad. Prefer explicit invocation by skill name when using it, and consider narrowing the publisher's trigger terms before relying on implicit activation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are broad, awkwardly phrased, and include generic terms like "security," "first," and "github," which can cause the skill to activate in unrelated contexts. In an agent environment, over-broad activation can route sensitive or irrelevant user requests into this workflow unexpectedly, increasing the chance of incorrect guidance, unintended actions, or prompt-surface abuse through accidental invocation.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrases are broad, generic, and include common words such as security, first, github, and bug fix, which can cause unintended invocation in unrelated conversations. In an agentic workflow, accidental routing to this skill can expose users to incorrect automation paths, unintended actions, or security-review behaviors when the user did not intend to invoke this capability.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger keyword list is overly broad and includes generic terms like "security," "first," "before," and "github," which are likely to appear in ordinary conversations unrelated to this skill. This can cause unintended auto-activation, expanding the skill's influence beyond user intent and potentially routing unrelated sensitive tasks through an inappropriate workflow.

Vague Triggers

High
Confidence
92% confidence
Finding
The manifest description instructs activation for broad categories like "work-productivity" and "security" and for vague needs such as any request for a "practical workflow, artifact, checklist, analysis, or implementation support." Such ambiguous activation guidance increases the chance of accidental invocation in many unrelated contexts, which can interfere with safer or more appropriate skill selection.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The example trigger phrases are highly generic and effectively mirror normal user requests for help, rather than demonstrating clear, bounded invocation syntax. Because examples often shape matching behavior and downstream expectations, weak examples increase the risk of over-triggering and user confusion about when this skill should apply.

Vague Triggers

High
Confidence
95% confidence
Finding
触发关键词包含如“security”、“first”、“before”、“github”等非常常见且语义宽泛的词,会让该技能在大量无关场景下被意外激活。对于一个涉及安全审查与工作流建议的技能,误触发可能导致覆盖更合适的技能、引入不相关安全建议,或让代理在错误上下文中执行高权限分析流程。

Vague Triggers

Medium
Confidence
88% confidence
Finding
技能描述将适用范围扩展到“work-productivity, skill-vetter, vetter, security, first”及任何需要流程、清单、分析或实现支持的场景,边界非常模糊。这样的宽泛激活面会增加错误路由概率,尤其在“security”等高敏感主题下,可能让用户请求被不恰当地导向本技能而非更专门、更安全的能力。

Natural-Language Policy Violations

Medium
Confidence
72% confidence
Finding
该文件仅提供中文版本内容,未体现基于用户偏好的语言协商机制,可能导致代理默认输出与用户语言不匹配。虽然这通常不是直接安全漏洞,但在安全审查、配置修复或操作步骤场景中,语言不匹配会降低理解准确性,增加误操作或遗漏关键警告的风险。

Vague Triggers

High
Confidence
94% confidence
Finding
The default prompt contains very broad natural-language trigger terms such as 'help me' and generic workflow/security phrasing, which can overlap with ordinary user requests and cause unintended invocation. Because implicit invocation is enabled, this increases the chance the skill is selected when the user did not explicitly request it, potentially injecting its prompt and behavior into unrelated conversations.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger sentences and keywords are broad enough to match common terms like "security," "first," "before," and "github," which can cause the skill to activate in conversations that were not actually asking for this workflow. Unintended invocation is dangerous because it can hijack routing, override more appropriate skills, or cause an agent to apply security-vetting behavior in unrelated contexts, reducing reliability and potentially influencing sensitive decisions.

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.