Back to skill

Security audit

Work Productivity Skill Vetter Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a simple workflow/checklist helper with broad activation wording, but it does not install code, persist, or handle sensitive data.

Install this only if you want a broad Skill Vetter/workflow assistant. Be aware that its trigger terms are loose, so it may activate during ordinary security, GitHub, or bug-fix requests unless your agent lets you control implicit skill invocation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are broad and include generic terms like 'security', 'first', 'github', and bug-fix language, which can cause the skill to activate outside the user's intended context. Unintended invocation can route unrelated prompts into this skill's workflow, leading to incorrect handling, prompt hijacking opportunities, or accidental exposure of sensitive user context to the wrong skill logic.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrases are broad enough to match many ordinary requests such as generic 'security', 'first', 'github', or 'bug fix' queries, which can cause the skill to activate outside its intended scope. In an agent ecosystem, overbroad activation can route unrelated user tasks into this workflow, leading to confusing behavior, accidental execution of inappropriate guidance, and increased exposure to prompt-injection or unsafe downstream actions.

Vague Triggers

High
Confidence
95% confidence
Finding
The skill description is broad enough to match many ordinary requests, including generic terms like "security" and "first," which can cause unintended activation. Overbroad routing increases the chance that this skill intercepts unrelated tasks, leading to incorrect guidance, workflow confusion, or bypass of more appropriate specialized skills.

Vague Triggers

High
Confidence
98% confidence
Finding
The trigger keyword list includes vague and common words such as "security," "first," "before," and "github," which are likely to appear in many benign requests. This creates a high risk of accidental invocation and prompt-surface expansion, where the skill influences conversations outside its intended scope.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The example trigger sentences reinforce permissive activation by showing highly generic phrasings rather than bounded, task-specific requests. This trains routing behavior toward overmatching and makes it more likely the skill will be selected for loosely related prompts.

Vague Triggers

High
Confidence
96% confidence
Finding
触发关键词包含非常宽泛且高频的通用词,如“security”“first”“before”“github”“bug fix”,会让该技能在大量无关场景中被误触发。误触发会把与当前任务无关的流程或指令注入会话上下文,增加错误建议、权限边界混淆和对其他更合适技能的覆盖风险。

Vague Triggers

Medium
Confidence
89% confidence
Finding
技能描述的启用条件覆盖“work-productivity, skill-vetter, vetter, security, first”以及‘practical workflow, artifact, checklist, analysis, implementation support’等宽泛需求,边界不清晰。这样的范围膨胀会导致技能在大量普通生产力或安全相关请求中被激活,造成不当介入、上下文污染和错误路由。

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill enables allow_implicit_invocation without any narrow activation boundary, which means the agent may invoke this skill in response to loosely related requests. Because the skill is framed around broad productivity, security, workflow, checklist, and implementation support tasks, unintended activation could expose users to unreviewed behavior or cause the skill to influence conversations outside its intended scope.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The default prompt uses very broad, everyday language such as help, practical workflow, checklist, analysis, and implementation support, which overlaps with many normal user requests. Combined with implicit invocation, this increases the chance that the skill is auto-selected in contexts where the user did not intend it, creating prompt-scope confusion and raising the risk of inappropriate actions or misleading assistance.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentence is broad enough to match routine user phrasing such as requests for 'practical workflow' or 'help' around common topics, which can cause the skill to activate outside its intended scope. Over-broad activation in a security-adjacent skill increases the chance of irrelevant or authority-inflating responses being injected into unrelated conversations, reducing user control and potentially bypassing more appropriate routing.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The activation guidance lists broad keywords like 'security', 'first', 'github', and 'bug fix' without boundaries, and it provides no negative examples to prevent accidental matches. This makes unintended invocation likely, especially in normal productivity or development conversations, which can misroute tasks and cause the skill to influence outputs in contexts the user did not intend.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.