Back to skill

Security audit

Work Productivity Skill Vetter Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with sloppy, overly broad activation text but no evidence of hidden execution, data access, persistence, or destructive behavior.

Before installing, be aware this skill may be invoked for unrelated requests because its trigger words are broad and implicit invocation is enabled. It appears safe as a documentation/workflow helper, but the publisher should narrow triggers to explicit skill-vetting phrases.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger phrases are broad and include generic wording that could cause the skill to activate in contexts the user did not intend. In a security- and vetting-related skill, accidental invocation can misroute tasks, produce irrelevant security guidance, or interfere with safer skill selection, increasing the chance of incorrect analysis or workflow confusion.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are broad enough to activate on generic terms like 'security', 'first', 'github', or 'bug fix', which can cause the skill to be invoked outside its intended scope. In an agent ecosystem, overbroad activation can misroute user requests, interfere with other skills, and cause users to receive inappropriate workflow guidance for unrelated tasks.

Vague Triggers

High
Confidence
96% confidence
Finding
The skill description includes extremely broad trigger terms such as "security" and "first," which are common in unrelated user requests and can cause unintended auto-invocation. In an agent ecosystem, accidental activation can redirect workflows, inject irrelevant instructions into a conversation, and interfere with more appropriate skills, creating reliability and safety issues even without explicit malicious payloads.

Vague Triggers

High
Confidence
98% confidence
Finding
The keyword list contains ambiguous single-word activators including "security," "first," "before," and "github," all of which are widely used across normal conversations. This makes over-triggering likely, allowing the skill to activate in contexts far outside skill vetting, which can confuse agent routing and increase the chance of unsafe or irrelevant guidance being inserted into tasks.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The example trigger sentences are malformed, incomplete, and not representative of realistic user requests, which weakens activation quality and increases misclassification risk. Poor examples can train or bias invocation logic toward noisy matches, compounding the already broad trigger definitions and making accidental activation more likely.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger keywords are overly broad and include common terms like 'security', 'first', 'before', and 'github', which can cause the skill to activate in many unrelated conversations. This creates routing ambiguity and can lead to inappropriate invocation, confusing outputs, or interference with higher-priority skills in security-sensitive contexts.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The description says the skill should be used when a user asks for broad categories like work-productivity, security, or practical support, but it does not clearly define scope limits. Ambiguous activation criteria can cause accidental triggering for unrelated requests, reducing predictability and potentially misdirecting users during sensitive security workflows.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The default prompt includes very broad trigger language such as 'help me' and generic work/productivity phrasing, which can cause the skill to activate in unrelated conversations. Because implicit invocation is enabled, this increases the chance of unintended routing, where user data or requests are sent to this skill without a clear, scoped user intent.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger phrases are broad enough to match common requests like 'security', 'github', 'bug fix', or 'I need a practical workflow', which can cause the skill to activate outside its intended scope. Over-broad activation increases the chance that unrelated user tasks are routed through this skill, leading to inappropriate handling, prompt interference, or accidental prioritization of this workflow over safer or more relevant skills.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.