Back to skill

Security audit

Work Productivity Skill Vetter Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with no executable code, but its activation wording is too broad and may invoke it for unrelated security or GitHub requests.

Install only if you are comfortable with a broad workflow-helper skill being implicitly selected for some security, GitHub, bug-fix, or checklist requests. The safer configuration would narrow triggers to explicit Skill Vetter or ClawHub skill-vetting phrases, or disable implicit invocation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger sentences are broad, natural-language phrases that could match ordinary user requests unrelated to deliberate invocation of this skill. In an agent ecosystem, this raises the chance of accidental activation, causing the wrong workflow to run, potentially exposing repository contents or steering security-sensitive tasks without clear user intent.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger keywords and example phrases are broad enough to match common user requests such as 'security', 'first', 'github', or generic bug-fix/help queries. This can cause the skill to activate in situations far outside its intended scope, increasing the chance of unintended handling of unrelated tasks and creating confusing or unsafe workflow routing in security-sensitive contexts.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger keywords include extremely broad terms such as "security," "first," "before," and "github," which overlap with ordinary user language and can cause the skill to activate in many unrelated conversations. In an agent environment, this increases the chance of unintended routing, instruction injection surface expansion, and execution of an irrelevant workflow in contexts where the user did not intend to invoke this skill.

Vague Triggers

High
Confidence
95% confidence
Finding
The manifest description says to use the skill when a user asks for broad topics like "security" or "implementation support," which creates ambiguous activation guidance at the metadata level. Because manifest descriptions are often used by selection and routing systems, this can cause the skill to be chosen for overly broad classes of requests, leading to misapplication of the skill and potential interference with more appropriate security-sensitive workflows.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The example trigger sentences are malformed, incomplete, and do not clearly show where invocation starts and ends, which makes trigger behavior harder to reason about and validate. Poorly specified examples can contribute to accidental activation patterns, inconsistent routing, and operator confusion during testing or deployment, though the direct security impact is somewhat lower than the broad keyword issues.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger list includes broad generic terms such as "security", "first", "before", and "github", which can cause the skill to activate in many unrelated conversations. Over-broad activation increases the chance of unintended routing, causing users to receive irrelevant workflow guidance or have higher-risk content handled by the wrong skill.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The description says to use the skill whenever users mention broad topics like work-productivity, security, or need general workflows, checklists, analysis, or implementation support for the requirement. This boundary is vague enough that the skill may be invoked outside its intended niche, leading to misrouting and unreliable behavior.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The default prompt is phrased as a broad natural-language trigger ('help me ...') tied to generic productivity and security-related terms, while implicit invocation is enabled. This can cause the skill to activate in unrelated conversations, increasing the chance of unintended prompt injection exposure, context leakage into the skill, or accidental execution of a workflow the user did not explicitly request.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger sentences and keywords are broad enough to match many ordinary requests about security, GitHub, bug fixes, or workflows, which can cause this skill to activate outside its intended scope. Over-broad routing can misapply workflow instructions, crowd out more appropriate skills, and create a confused-deputy risk where users are steered into security-adjacent actions without clearly asking for this specific capability.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.