Back to skill

Security audit

Work Productivity Skill Vetter Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper, but its activation terms are too broad and may cause it to appear in unrelated conversations.

Install only if you want a Skill Vetter workflow helper that may be invoked broadly. Consider narrowing or disabling implicit triggers if your agent environment routes skills automatically, especially for generic security or GitHub-related requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrases are broad, generic, and include common terms like 'security', 'github', 'first', and 'bug fix', which can cause the skill to activate for unrelated user requests. In an agent ecosystem, overly broad routing can misapply this skill's workflow to conversations the user did not intend, leading to incorrect handling, confusion, or unsafe delegation decisions.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrases are extremely broad, including generic terms such as "security," "first," "before," and "github," which can cause the skill to activate in many unrelated conversations. In an agent ecosystem, overbroad routing increases the chance that this workflow intercepts requests it was not intended to handle, leading to incorrect guidance, workflow confusion, or accidental precedence over more appropriate skills.

Vague Triggers

High
Confidence
98% confidence
Finding
The skill description includes very broad activation terms such as "security" and "first," which are common in normal user requests and can cause the skill to activate outside its intended scope. Over-broad routing increases the chance of context hijacking, incorrect tool selection, or accidental invocation during unrelated tasks, especially in multi-skill agent environments.

Vague Triggers

High
Confidence
99% confidence
Finding
The keyword list contains ambiguous single words and generic terms including "security," "first," "before," and "github," all of which appear in many benign conversations. In an automated skill-selection system, this can lead to frequent unintended activation, causing the agent to follow the wrong workflow or expose users to misleading security-oriented outputs when they did not request this skill.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The example trigger sentences are malformed and overly vague, so they fail to communicate a clear activation boundary and may train matching systems on noisy patterns. This ambiguity makes accidental invocation more likely and weakens operator understanding of what user intent should actually map to this skill.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger list includes very broad everyday terms such as "security", "first", "before", and "github", which can cause the skill to activate in many unrelated conversations. Over-broad activation increases the chance that this workflow hijacks user intent, injects irrelevant instructions, or interferes with more appropriate skills, which is a real safety and reliability issue in agent routing.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The description says to use the skill when a user asks for broad categories like work-productivity, security, or practical workflow support, without clearly bounding the task type. This ambiguous enablement scope can make the skill eligible for many unrelated requests, leading to accidental invocation and unsafe or confusing cross-task behavior.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The default prompt includes very broad, everyday trigger terms and a generic invocation pattern, which can cause the skill to activate in contexts where the user did not clearly intend it. Because this skill is security- and workflow-related and implicit invocation is enabled, accidental routing could expose unrelated conversations to an over-privileged or safety-sensitive helper, increasing the risk of prompt hijacking, context confusion, or unintended actions.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentences include broad, common terms such as "help me," "practical workflow," and generic security/work-productivity phrasing that can cause the skill to activate outside its intended scope. In an agent environment, this increases the chance of unintended routing, prompt hijacking via incidental keyword overlap, or execution of this workflow when a more appropriate and safer skill should handle the request.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.