Back to skill

Security audit

Work Productivity Skill Vetter Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a low-impact workflow/helper skill with overly broad activation wording, but it does not request privileged access, persistence, credentials, or destructive behavior.

Install only if you want a general workflow helper for Skill Vetter-style review and improvement tasks. Be aware that its broad trigger wording may activate it for ordinary security, GitHub, or bug-fix requests, so explicit invocation or tighter trigger wording would make it more predictable.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrases are broad, generic help-seeking language that can match many ordinary user requests unrelated to this specific skill. In an agent environment, this can cause unintended auto-invocation, routing users into a security/vetting workflow when they did not ask for it, increasing confusion and the chance that the wrong skill handles sensitive tasks.

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger phrases are broad enough to match ordinary user requests about security, GitHub, bug fixes, or general workflow help, which can cause the skill to activate outside its intended scope. In an agent environment, overbroad activation can override more appropriate skills or inject this workflow into unrelated tasks, reducing reliability and potentially affecting security-sensitive decision paths.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The invocation guidance does not define boundaries for when the skill should or should not be used, so an orchestrator or user may invoke it for many generic productivity or security requests. This ambiguity increases the chance of misrouting tasks, especially because the skill advertises broad terms and lacks exclusion criteria for unrelated contexts.

Vague Triggers

High
Confidence
97% confidence
Finding
The skill description includes extremely broad activation terms such as 'security' and 'first' in a global 'Use when' clause, which can cause the skill to trigger in many unrelated conversations. Over-broad routing can silently inject the skill's workflow into contexts where it was not requested, leading to inappropriate handling, prompt-context pollution, or bypass of more suitable specialized skills.

Vague Triggers

High
Confidence
99% confidence
Finding
The keyword list contains vague everyday terms including 'security', 'first', 'before', and 'github', all of which are common across unrelated requests. This materially increases accidental invocation risk, allowing the skill to overmatch normal user language and interfere with routing or introduce irrelevant instructions into benign tasks.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The example trigger phrases are truncated, ambiguous, and broad enough that they do not define clear activation boundaries. Poor examples reinforce loose matching behavior and make it easier for the skill to activate on partial or incidental phrasing rather than deliberate user intent.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger keywords are overly broad, especially generic terms like "security", "first", "before", and "github". This can cause the skill to activate in unrelated conversations, creating routing confusion and potentially injecting this skill's workflow into contexts where it was not requested, which is a prompt-scope and reliability risk.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The description says to use the skill when users ask for broad concepts like work-productivity, security, or practical support, but it does not clearly bound the activation conditions. Ambiguous invocation rules increase the chance of unintended skill selection, which can mis-handle user intent or expose the system to prompt-routing abuse.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The default prompt contains a very broad activation phrase and the policy explicitly allows implicit invocation, which increases the chance this skill will be triggered by ordinary user language rather than deliberate selection. In a security- and workflow-oriented skill, unintended invocation can cause confusing routing, accidental disclosure of task context to the skill, or unexpected execution of guidance in situations where the user did not intend to use it.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentences are written as broad natural-language phrases that can match many ordinary requests unrelated to this specific skill. In an agent-routing context, this can cause unintended auto-activation, leading the skill to receive conversations it was not explicitly selected for and potentially influencing security-sensitive workflows under false pretenses.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The keyword list includes generic terms like 'security', 'first', 'before', 'github', and 'bug fix', which are common across many unrelated tasks. Overbroad trigger scope increases the chance of misrouting prompts into this skill, where it may shape outputs or analyses in situations the user did not intend, reducing trustworthiness and creating opportunity for prompt-scope abuse.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.