Back to skill

Security audit

Skill Vetter Workflow Helper

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a workflow-helper skill with overly broad activation wording, but no evidence of hidden execution, data theft, destructive behavior, or privilege abuse.

Review the trigger wording before installing if you rely on precise skill routing; it may activate for generic security, GitHub, workflow, or checklist requests. Otherwise, the available evidence supports treating it as a normal low-impact guidance skill.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are broad, generic, and include common terms such as 'security', 'github', and 'bug fix', which can cause the skill to activate in unrelated contexts. In an agent ecosystem, overbroad activation can route sensitive or unrelated user requests into this skill unexpectedly, increasing the chance of incorrect handling, prompt interference, or misuse of security-oriented workflows.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger phrases are broad enough to match common requests such as 'security', 'first', 'before', or 'github', which can cause the skill to activate in unrelated conversations. In an agent ecosystem, overbroad activation can misroute user intent, cause inappropriate workflow injection, and increase the chance that users rely on the wrong automation for security-sensitive tasks.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger keywords are extremely broad, including common terms like "security," "first," "before," and "github," which can cause the skill to activate in many unrelated conversations. In an agent environment, this increases the chance of unintended routing or priority hijacking, where this skill intercepts requests outside its intended scope and influences security-sensitive workflows.

Vague Triggers

High
Confidence
94% confidence
Finding
The manifest description says to use the skill when a user asks for very broad concepts like "security," "first," or any practical workflow or checklist, creating an ambiguous activation boundary. This can make the skill eligible for many unrelated prompts, increasing accidental invocation and making it easier for the skill to shape responses in contexts the user did not intend.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger keywords include very generic terms such as "security", "first", "before", "github", and "bug fix", which are likely to appear in ordinary user conversations unrelated to this skill. This can cause accidental activation, resulting in the wrong workflow being injected into conversations and potentially steering security-sensitive tasks with irrelevant or unintended guidance.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The invocation description says to use the skill for broad topics like work-productivity, vetter, security, or practical workflow support, without clearly bounding the situations where it applies. This ambiguity increases the chance the system will select the skill for unrelated requests, causing misrouting and reducing reliability in contexts that may already be sensitive, such as security reviews.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The default prompt activates on very broad everyday terms such as 'work-productivity', 'security', 'first', 'workflow', 'checklist', and 'analysis' without clear scoping. This can cause unintended invocation in unrelated conversations, leading the agent to inject this skill's behavior or guidance when the user did not explicitly request it, which is especially risky for a security-oriented helper because it may influence sensitive decision-making or override user intent.

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger sentences are broad and include common terms like 'security', 'first', 'before', and generic requests for 'practical workflow', which can cause the skill to activate in many unrelated contexts. Over-broad invocation increases the chance that this skill intercepts prompts it should not handle, leading to workflow confusion, incorrect task routing, and potential exposure of users to security-analysis behavior when they intended something else.

Static analysis

No suspicious patterns detected.