Back to skill

Security audit

Work Productivity Skillscan Security Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with no executable code or data access, but its activation terms are too broad and could cause accidental use.

Install only if you want a broad workflow helper for SkillScan-style security and reliability tasks. The publisher should narrow the trigger terms or disable implicit invocation to reduce accidental activation, but no executable or credential-handling behavior was found in the inspected files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (13)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger sentences are written so broadly that they can match ordinary user requests unrelated to this specific skill, causing unintended activation. In an agent ecosystem, this can route users into the wrong workflow, override more appropriate skills, and increase the chance that security-sensitive actions are performed under incorrect assumptions.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The keyword list includes highly generic terms like "security," "gate," "every," "must," and "pass," which are common in normal conversation and therefore create an ambiguous activation boundary. This increases the risk of accidental skill invocation, workflow hijacking, or interference with unrelated tasks, especially in multi-skill agent environments.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger phrases are broad natural-language prompts that can match ordinary user requests unrelated to this specific skill, increasing the chance of accidental activation. In an agentic system, unintended invocation can route tasks through the wrong workflow, causing incorrect security handling, user confusion, or overbroad access to tooling intended only for specialized use.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The keyword list includes highly generic terms such as 'security', 'gate', 'every', 'must', 'pass', 'before', 'activate', and 'bug fix', which are common across many unrelated conversations. This ambiguity can cause frequent false activations, especially in environments where routing decisions depend on simple keyword matching, leading to workflow hijacking or misapplication of the skill.

Vague Triggers

High
Confidence
97% confidence
Finding
The skill description and usage guidance are broad enough to match common security- and productivity-related requests without clear boundaries, which can cause unintended activation. In an agent system, overbroad activation can misroute sensitive tasks, override more appropriate skills, or widen the attack surface for prompt-injection-style steering through generic keywords.

Vague Triggers

High
Confidence
99% confidence
Finding
The trigger list includes highly generic words such as 'security', 'gate', 'every', 'must', 'pass', and 'before', which are likely to appear in many unrelated prompts. This makes accidental invocation very likely and creates a routing vulnerability where benign or sensitive requests could be captured by this skill unexpectedly.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The example trigger sentences demonstrate activation on vague, partial phrases rather than well-defined task boundaries, reinforcing permissive matching behavior. This increases the chance that the orchestrator or author copies unsafe activation patterns, leading to skill selection errors and reduced predictability.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger list includes very broad everyday terms such as "security", "every", "must", "pass", and "before", which can match many unrelated user requests and cause accidental activation. In a security-oriented skill, unintended invocation is risky because the agent may apply this workflow in the wrong context, overriding more appropriate skills or injecting irrelevant security guidance into unrelated tasks.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The description says to use the skill when users ask for broad categories like work-productivity, skillscan, security, gate, or every, or whenever they need practical workflow or analysis support for the requirement, but it does not define clear boundaries for when this skill should or should not be selected. This ambiguity increases the chance of over-triggering and misrouting requests, which can degrade reliability and produce inappropriate guidance in non-target contexts.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The default prompt is overly broad and includes generic help-oriented language, which can cause the skill to be selected for loosely related requests rather than explicit user intent. In a security workflow helper, accidental invocation can expose users to unintended actions, irrelevant guidance, or routing into a security-sensitive workflow without clear consent.

Vague Triggers

High
Confidence
96% confidence
Finding
Enabling implicit invocation without strong activation constraints allows the skill to auto-trigger from ambiguous requests. Because this skill is framed around security, bug fixing, hardening, and implementation support, incorrect activation could steer user interactions into sensitive domains, increase prompt-surface area, and create opportunities for misrouting or unintended execution paths.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentence includes extremely broad, everyday terms like "security," "gate," and "every," which can cause the skill to activate for many unrelated requests. Overbroad activation can route users into the wrong workflow, increasing the chance of unintended execution paths, incorrect assistance, or abuse through prompt steering.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger description does not define clear boundaries for when the skill should and should not activate, so invocation is ambiguous. In an agent environment, ambiguous routing increases the risk of accidental activation on unrelated tasks, which can leak context across workflows or produce misleading security guidance.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.