Back to skill

Security audit

Work Productivity Skill Vetter Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a non-executable workflow helper, but its automatic activation terms are overly broad and could cause accidental use.

Install only if you are comfortable with this skill being invoked from broad terms like security, github, or bug fix. For safer use, prefer explicit invocation by skill name or narrow the trigger list before publishing or installing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrases are broad, generic, and include common terms like "security," "first," and "github," which can cause the skill to activate in contexts the user did not intend. In an agent ecosystem, overbroad activation can route unrelated requests into this workflow, leading to inappropriate guidance, confusing behavior, or unintended processing of sensitive tasks under the wrong skill.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrases are broad and include generic terms like 'security', 'first', 'before', 'github', and 'bug fix', which can cause the skill to activate in many unrelated contexts. In an agent ecosystem, unintended invocation can redirect user workflows, apply the wrong instructions, or expose the agent to adversarial prompt-routing behavior, making this a real security and reliability issue.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger keywords are overly broad, including generic terms like "security," "first," and "github," which can cause the skill to activate for many unrelated user requests. This creates scope hijacking risk where the wrong skill is invoked, potentially steering sensitive or routine conversations into an unintended workflow and degrading reliability or safety review quality.

Vague Triggers

High
Confidence
95% confidence
Finding
The manifest description uses broad activation language like "use when a user asks for work-productivity, skill-vetter, vetter, security, first" and also claims many kinds of support including analysis, checklist, artifact, and implementation help. This ambiguity increases accidental activation and lets the skill match normal conversation patterns far outside its intended domain.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The example trigger sentences are malformed, repetitive, and too vague to establish a precise activation boundary. Poor examples reinforce broad matching behavior and make it harder for maintainers or routing systems to distinguish legitimate invocations from unrelated prompts.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger list includes very generic terms such as "security", "first", "before", and "github", which are common in ordinary user conversations and can cause the skill to activate unintentionally. This increases the chance of prompt-routing collisions, causing the wrong workflow to run, potentially overriding more appropriate skills or injecting irrelevant instructions into sensitive security-related interactions.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The activation description says to use the skill for broad topics like work-productivity, security, and practical support, but does not clearly define boundaries or exclusion criteria. That ambiguity can cause over-activation in unrelated contexts, reducing routing accuracy and potentially surfacing this skill during conversations where a more specialized or safer skill should handle the request.

Vague Triggers

High
Confidence
94% confidence
Finding
The default prompt is written as a broad natural-language trigger and includes generic terms like 'help me' plus a long, vague problem description, which increases the chance of accidental activation during ordinary user conversations. In an implicitly invokable skill, this can cause the agent to route sensitive or unrelated requests into this workflow without clear user intent, creating prompt-routing confusion and possible unauthorized handling of context.

Vague Triggers

High
Confidence
97% confidence
Finding
Enabling implicit invocation without strong trigger constraints makes the skill callable from ambiguous user input, especially because the skill description targets broad concepts like productivity, security, workflows, and checklists. This expands the attack surface for misrouting, unintended execution, and prompt-injection chaining where unrelated conversations may silently activate the skill and expose internal instructions or influence agent behavior.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger examples are broad, natural-language phrases that overlap with ordinary user requests, which can cause the skill to activate outside its intended scope. In a security- and workflow-oriented skill, overbroad activation can route unrelated conversations into this skill unexpectedly, increasing the chance of misapplied guidance, prompt-surface expansion, or unintended interference with other skills.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The activation scope is described loosely through keywords and sample sentences without hard boundaries, making it unclear when the skill should or should not run. Ambiguous routing is dangerous because it can cause unintended invocation on benign requests, reduce predictability, and expose users to outputs or workflows that were not requested.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.