Back to skill

Security audit

Work Productivity Skill Vetter Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-style workflow helper with no executable code, credential handling, persistence, or hidden data movement, though its activation wording is too broad.

Installers should narrow the trigger keywords and examples before publication so this helper is invoked only for explicit Skill Vetter or skill-review workflow requests. As inspected, it does not ask for credentials, run commands, persist state, or move data, so the main risk is confusing or unwanted activation rather than direct security harm.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrases are broad, generic, and include common terms like 'security', 'first', 'github', and 'bug fix', which can cause the skill to activate for unrelated everyday requests. In an agent ecosystem, overbroad activation increases the chance of unintended routing, context confusion, and accidental invocation of a workflow that may influence sensitive security-related decisions.

Vague Triggers

High
Confidence
92% confidence
Finding
The trigger phrases are broad and include common terms like "security", "first", "before", and "github", which can cause the skill to activate in many unrelated conversations. In an agent environment, overbroad activation can misroute user requests into this workflow unexpectedly, creating prompt-scope confusion and increasing the chance of unintended execution paths or irrelevant guidance.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger keywords are extremely broad, including generic terms like 'security', 'first', 'before', and 'github', which are likely to match ordinary user conversation unrelated to this skill. This can cause unintended activation and context hijacking, where the skill injects workflow guidance into unrelated tasks and may override more appropriate specialized handling.

Vague Triggers

High
Confidence
95% confidence
Finding
The manifest description says to use the skill when a user asks for broad categories like 'security', 'first', or any practical workflow or analysis support, which creates an activation condition with almost no meaningful boundary. In a dispatcher or auto-routing system, this makes accidental invocation likely and can lead to incorrect tool selection, prompt interference, or dilution of safer, task-specific controls.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The example triggers are malformed, vague, and partially broken sentences, so they do not constrain activation behavior or teach users and orchestrators what valid invocation looks like. Poor trigger examples increase misrouting risk because systems may fall back to the already-overbroad keywords rather than precise, intentional patterns.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger keywords include very common terms such as "security", "first", "before", and "github", which can cause the skill to activate in many unrelated conversations. In an agent environment, overbroad activation can route sensitive or irrelevant tasks into this workflow unexpectedly, increasing the chance of incorrect guidance, prompt interference, or policy bypass through unintended skill invocation.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The description says to use the skill when users ask for broad categories like work-productivity, security, or practical workflow support, but it does not clearly bound the scope. This ambiguity makes accidental invocation more likely and can cause the agent to apply this skill outside its intended context, reducing reliability and potentially mishandling user requests.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The default prompt contains a very broad natural-language trigger phrase tied to common terms like 'help me' and generic productivity/security workflow wording, which increases the chance of unintended invocation during ordinary user conversations. Because implicit invocation is enabled, this can cause the skill to activate when the user did not explicitly intend it, leading to prompt-context injection, workflow hijacking, or unexpected handling of sensitive requests.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentences contain broad, everyday phrasing such as 'Help me' and 'I need a practical workflow' combined with loosely related requirement text, which can cause the skill to activate in many benign conversations that were not actually requesting this specific capability. Over-broad invocation increases the chance of unintended routing into a security- or vetting-oriented workflow, which can confuse execution, override more appropriate skills, and expand the attack surface for prompt-trigger manipulation.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The activation guidance is too generic and does not define precise trigger boundaries, so the skill may be selected based on weak keyword overlap rather than clear user intent. In a multi-skill environment, this can lead to accidental invocation, misrouting of user requests, and reduced trust in security-related workflows because the wrong artifact or analysis may be produced.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.