Back to skill

Security audit

Work Productivity Skill Vetter Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with no code execution or data access, though its activation terms are broader than they should be.

Before installing, be aware that this skill may be selected for generic security, GitHub, or bug-fix requests because its triggers are broad and implicit invocation is enabled. It is otherwise low-risk as published, but the publisher should narrow activation to explicit skill-vetting or ClawHub review requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger sentences are broad enough to match common requests about security, GitHub, bug fixing, or practical workflows, which can cause the skill to activate in contexts the user did not explicitly intend. In an agent ecosystem, overbroad invocation increases the chance of misrouting user tasks into this skill, potentially bypassing more appropriate or safer workflows and producing misleading security-related guidance.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger phrases are broad enough to match generic security, GitHub, or bug-fix requests that may be unrelated to this skill, increasing the chance of accidental activation or misrouting. In an agent ecosystem, ambiguous invocation can cause the wrong workflow to run, leading to inappropriate guidance, confused task execution, or unsafe handling of security-sensitive requests.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger keywords are extremely broad and include common terms like "security," "first," and "github," which can cause the skill to activate in many unrelated conversations. Overbroad activation increases the chance that the skill injects workflow instructions or analysis into contexts where it was not requested, creating prompt-routing confusion and potentially interfering with safer or more appropriate skills.

Vague Triggers

High
Confidence
96% confidence
Finding
The manifest description defines invocation conditions using vague, high-frequency terms and broad task categories like "security," "first," and "practical workflow," which are likely to match ordinary user requests outside this skill's intended scope. Because manifest metadata is often used for skill selection, this ambiguity can cause unintended auto-invocation and misrouting of user prompts.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The example trigger sentences are fragmented, unrealistic, and fail to establish clear activation boundaries, which weakens any downstream classifier or matcher that relies on examples for routing behavior. Poor examples can train or signal the system to activate on partial, ambiguous phrases rather than clear user intent.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger list includes overly broad common terms such as "security", "first", "before", and "github", which can cause the skill to activate in many unrelated conversations. In an agent environment, unintended activation can override more appropriate skills, inject irrelevant workflow steps into security-sensitive tasks, and increase the chance of prompt-confusion or unsafe automation being applied out of context.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The description says to use the skill when a user asks for broad topics like work-productivity, security, or practical workflow support, but it does not clearly define when the skill should not apply. This ambiguous enablement scope increases the risk of accidental invocation for unrelated requests, which can misroute the agent and degrade safety decisions in contexts where precise skill selection matters.

Vague Triggers

High
Confidence
95% confidence
Finding
The default prompt contains very broad trigger terms such as "work-productivity," "security," and "first," which are common in ordinary user requests and can cause unintended or overly eager skill invocation. In a security-oriented helper, accidental activation is risky because it may inject unrelated workflow guidance or analysis behavior into conversations where the user did not explicitly request this skill.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentences are broad, everyday phrases like 'help me' and 'I need a practical workflow,' which can cause the skill to activate in contexts far beyond the intended requirement. In a security- or workflow-oriented skill, overbroad activation increases the chance of unintended invocation, context capture, or the skill steering unrelated conversations into its workflow without clear user intent.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.