Back to skill

Security audit

Work Productivity Skillscan Security Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

The skill is documentation-only and not destructive, but its implicit activation is under-scoped and can trigger on very generic requests.

Install only if you want this skill to be considered for broad security, bug-fix, and workflow requests. Prefer narrowing or disabling implicit invocation so it activates only for explicit SkillScan or ClawHub skill-review workflow requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger sentence is broad enough to match ordinary user requests about help, workflows, bug fixing, or hardening without clearly requiring an explicit invocation. This can cause unintended activation of the skill in unrelated contexts, leading to prompt-routing errors, confused delegation, or accidental application of security-oriented workflow behavior where it was not requested.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The keyword list contains highly generic terms such as 'security', 'every', 'must', 'pass', 'before', and 'bug fix', which overlap heavily with normal conversation and many unrelated tasks. In an agent ecosystem, this ambiguity increases the chance of overbroad routing or invocation collisions, making the skill easier to trigger accidentally and potentially interfering with safer or more relevant skills.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger phrases are broad enough to match common words and generic requests, which can cause the skill to activate outside its intended security-workflow context. In an agent environment, overbroad activation can route unrelated user tasks through this skill, creating prompt-surface expansion, confusing behavior, and increasing the chance that sensitive or high-trust workflows are invoked unintentionally.

Vague Triggers

High
Confidence
97% confidence
Finding
The skill description says to use the skill when a user asks for very broad terms like "security," "checklist," "analysis," or "implementation support," which are common across many unrelated tasks. This can cause the skill to auto-match outside its intended scope, leading to incorrect routing, unintended instruction injection into unrelated workflows, or over-application of the skill in sensitive contexts.

Vague Triggers

High
Confidence
99% confidence
Finding
The keyword list includes generic words such as "security," "gate," "every," "must," "pass," and "before," which are likely to appear in ordinary user requests unrelated to this skill. Overbroad triggers increase accidental activation risk and may hijack routing decisions, especially in multi-skill agent systems where trigger precision is a security boundary.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example trigger sentences are vague and mostly repeat the requirement language without showing clear boundaries for when the skill should or should not activate. Ambiguous examples train integrators toward permissive matching behavior, which makes false activation and misrouting more likely.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger list is overly broad, including generic terms like "security", "gate", "every", "must", and "before", which can cause the skill to activate in many unrelated conversations. In an agent environment, unintended activation can override more appropriate skills, inject irrelevant workflow behavior, and increase the chance of unsafe or incorrect task handling.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The invocation description says to use the skill for broad categories and vague needs like workflows, artifacts, checklists, analysis, or implementation support, without defining strict scope boundaries. This ambiguity increases accidental routing and may cause the skill to engage in contexts it was not designed for, reducing reliability and potentially affecting security-sensitive decisions.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The default prompt contains a very broad invocation phrase tied to common terms like 'work', 'productivity', 'security', and 'workflow', while implicit invocation is enabled. This increases the chance the skill will be triggered during ordinary user conversations and inject its prompt or behavior unexpectedly, which can override user intent, create prompt confusion, or cause unauthorized workflow execution.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger list includes very broad, everyday words such as 'security', 'gate', 'every', 'must', 'pass', 'before', and 'activate', which can cause the skill to activate for many unrelated requests. This creates unintended routing risk: users may be sent into this skill when they did not ask for it, potentially overriding more appropriate skills or causing incorrect workflow execution.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.