Back to skill

Security audit

Work Productivity Skill Vetter Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-style workflow helper with no executable code, but its broad trigger terms could make it activate in unrelated requests.

Before installing, consider narrowing the trigger keywords or disabling implicit invocation so ordinary security, GitHub, or bug-fix requests do not route through this workflow helper by accident. The reviewed artifacts do not show malicious behavior or privileged execution.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are extremely broad and include common security and workflow terms like 'security', 'first', 'before', and 'github', which can cause the skill to activate in many unrelated contexts. In an agent environment, overbroad activation can misroute user requests, preempt more appropriate skills, and cause unintended handling of sensitive vetting or security tasks.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases are broad and include generic terms such as security, first, github, and bug fix, which can cause the skill to activate in many unrelated conversations. In an agent environment, over-broad activation can route sensitive or unintended tasks into this skill, increasing the chance of incorrect handling, context leakage, or unsafe workflow execution.

Vague Triggers

High
Confidence
97% confidence
Finding
The skill description and activation guidance are broad enough to match many generic requests, especially because it claims applicability to common themes like productivity, security, and implementation help. In an agentic system, this can cause unintended invocation, injecting irrelevant or unreviewed workflow instructions into unrelated tasks and expanding the skill's effective authority beyond its intended scope.

Vague Triggers

High
Confidence
99% confidence
Finding
The keyword list includes vague, high-frequency words such as 'security', 'first', 'before', and 'github' that appear in many unrelated prompts. This makes accidental triggering likely, which can route user requests through an unintended skill path and create prompt-scope confusion or policy bypass opportunities when the wrong instructions are introduced into the conversation.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The example trigger sentences are incomplete and loosely framed, so they do not establish a clear boundary for when the skill should activate. Ambiguous examples train routing systems and users toward overbroad invocation patterns, increasing the chance of misclassification and unintended use of this skill in contexts it was not designed to handle.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger list includes very generic terms such as 'security', 'first', 'before', and 'github', which are likely to appear in many unrelated user requests. This can cause unintended activation of the skill, leading to misrouting, confusing behavior, and possible interception of requests that should have gone to a more appropriate or safer skill.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The activation description says to use the skill for broad categories like work-productivity, security, or when users need practical workflow or analysis support, but it does not clearly distinguish this skill from many other general-purpose helper skills. Ambiguous routing criteria increase the chance of accidental invocation, which can degrade reliability and expose users to irrelevant or misleading guidance in security-sensitive contexts.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The default prompt contains broad, natural-language trigger terms such as "help me" and generic workflow language, while the policy also allows implicit invocation. This can cause the skill to activate in routine conversations without clear user intent, creating prompt-injection and unintended tool-use risk, especially for a security-oriented helper that may influence analysis or workflows.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger sentences and keyword list are broad enough that normal security, GitHub, or workflow-related requests could invoke this skill unintentionally. Over-broad activation can route users into the wrong workflow, causing confused-deputy behavior, irrelevant automation, or accidental execution of analysis steps in contexts the user did not intend.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.