Back to skill

Security audit

Work Productivity Skill Vetter Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overbroad activation wording, but no hidden execution, credential access, persistence, or data exfiltration behavior.

Before installing, be aware that this skill may be invoked too easily for general security, GitHub, or bug-fix requests. It appears safe as a workflow helper, but its triggers should ideally be narrowed to explicit skill-vetting or pre-installation review requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are generic and map to common terms like 'security', 'first', 'github', and 'bug fix', which can cause the skill to activate outside its intended scope. Over-broad activation increases the chance that unrelated user requests are intercepted and processed by the wrong workflow, creating security and reliability risks through misrouting and unintended behavior.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrases are very broad and include generic terms like "security," "first," "github," and "bug fix," which can cause the skill to activate in contexts unrelated to its intended purpose. In agent ecosystems, overbroad invocation increases the chance of unintended execution paths, confusing tool selection, and misuse in sensitive workflows.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger keywords are overly broad and include common terms like "security," "first," "before," and "github," which can cause the skill to activate for many unrelated conversations. This increases the chance of unintended routing or prompt injection exposure because the skill may engage in contexts where its instructions are not appropriate or expected.

Vague Triggers

High
Confidence
92% confidence
Finding
The manifest description says to use the skill when a user asks for broad categories like "security," "first," or any "practical workflow, artifact, checklist, analysis, or implementation support," which is ambiguous and likely to overmatch unrelated requests. Ambiguous activation guidance can make the orchestrator invoke this skill unexpectedly, leading to incorrect handling of user tasks and expanding the attack surface for malicious prompt content to reach the skill.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger list includes very broad everyday terms such as "security", "first", "before", and "github", which can cause the skill to activate in many unrelated conversations. Over-broad activation increases the chance that this skill intercepts requests outside its intended scope, leading to confusing behavior, prompt routing mistakes, or unreviewed workflow guidance being applied where it does not belong.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The description says the skill should be used when users mention broad categories like work-productivity, security, or need any practical workflow, checklist, analysis, or implementation support for the requirement. This boundary is vague enough that the skill may be selected for loosely related requests, increasing accidental invocation and making downstream behavior less predictable.

Vague Triggers

High
Confidence
95% confidence
Finding
The default prompt contains broad, common-language trigger terms such as 'help me' and generic productivity/security wording, which can cause the skill to be invoked in contexts the user did not clearly intend. Because implicit invocation is enabled, this increases the chance of accidental routing, prompt injection surface expansion, and user confusion about which skill is acting.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger phrases are so broad and awkwardly truncated that they can match ordinary user requests containing common words like 'help me', 'practical workflow', 'security', or 'github', causing the skill to activate outside its intended scope. In an agent-routing context, this can misroute unrelated conversations into a security/workflow skill, increasing the chance of inappropriate handling, prompt collisions, or accidental exposure of sensitive context to the wrong workflow.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.