Back to skill

Security audit

Work Productivity Skill Vetter Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with no executable code or persistence, though its auto-invocation wording is broader than ideal.

This skill is reasonable to install if you want workflow help for reviewing or improving Skill Vetter-style processes. Be aware that its activation rules are broad, so it may appear in unrelated security, GitHub, or bug-fix conversations unless your environment lets you disable implicit invocation or narrow triggers.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger sentences are broad, unnatural, and overlap with common security/workflow terms such as 'security', 'first', 'github', and 'bug fix', which increases the chance the skill is invoked in contexts the user did not clearly intend. In a security-adjacent skill, unintended activation can misroute sensitive vetting requests, cause the wrong workflow to run, or suppress use of a more appropriate specialized skill.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger phrases are extremely broad and include common words like "security," "first," "before," and "github," which can cause the skill to activate in many unrelated conversations. In an agent ecosystem, this creates prompt-routing confusion and can unintentionally invoke this skill in contexts where the user did not request it, leading to incorrect workflows, unexpected behavior, or interference with more appropriate skills.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The activation conditions are ambiguous because the skill mixes broad keywords with loosely defined example prompts, without clear boundaries for when invocation is appropriate. This ambiguity increases the chance of accidental activation, misrouting user intent, and overbroad interception of requests related only tangentially to productivity, vetting, or security.

Vague Triggers

High
Confidence
96% confidence
Finding
The manifest description includes highly generic activation terms such as "security," "first," and broad task phrases like "needs a practical workflow, artifact, checklist, analysis, or implementation support." This can cause the skill to activate for many unrelated requests, creating scope hijacking risk where the wrong skill is invoked and influences user workflows outside its intended boundary.

Vague Triggers

High
Confidence
98% confidence
Finding
The trigger keyword list contains ambiguous terms including "security," "first," "before," and "github," which are common across many benign conversations. Overbroad triggers increase accidental invocation and prompt-space capture, allowing this skill to insert itself into unrelated security or development tasks and potentially override more appropriate specialized skills.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The example trigger sentences are vague and effectively mirror generic productivity requests without clear eligibility rules. This reinforces overbroad routing behavior and makes it more likely that downstream systems or authors will treat loosely related requests as valid activations for this skill.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger keywords are overly broad, including generic terms like 'security', 'first', 'before', 'github', and 'bug fix'. This can cause the skill to activate in many unrelated conversations, leading to accidental routing, inappropriate guidance, or overshadowing more suitable skills, which is especially risky for a security-themed workflow helper because users may overtrust its relevance.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The skill description defines a very broad usage boundary: it can be used whenever a user mentions work-productivity, security, or asks for any practical workflow, checklist, analysis, or implementation support related to the requirement. This ambiguity makes mis-invocation likely, causing the skill to handle requests outside its intended scope and potentially provide misleading or overbroad security/process advice in contexts where a different specialized skill should respond.

Vague Triggers

High
Confidence
95% confidence
Finding
The default prompt trigger phrase is extremely broad and includes generic terms like work-productivity, security, practical workflow, checklist, and analysis support, which can overlap with ordinary user requests. This can cause the skill to be invoked unintentionally, injecting its behavior or instructions into unrelated conversations and increasing the risk of prompt-scope confusion or unsafe tool activation.

Vague Triggers

High
Confidence
98% confidence
Finding
Enabling implicit invocation without strict activation constraints allows the system to auto-activate this skill based on vague language rather than deliberate user intent. In a security- and workflow-related skill, this is especially risky because the assistant may begin applying vetting or workflow logic unexpectedly, potentially affecting outputs, trust boundaries, or downstream actions without clear user consent.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentences are broad, natural-language phrases that can match ordinary user requests such as asking for a practical workflow, help fixing bugs, or hardening setup. This increases the chance of unintended skill activation, causing the agent to invoke this skill in contexts where it was not explicitly requested, which can lead to incorrect routing, overbroad access to user context, or interference with safer/more specific skills.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.