Back to skill

Security audit

Agent Skill Design Patterns

Security checks across malware telemetry and agentic risk

Overview

This appears to be a skill-authoring guide with broad trigger wording, not a harmful or over-privileged skill.

Install this if you want help designing OpenClaw skills or templates. Be aware it may trigger on generic phrases about creating or reviewing skills, so use explicit wording when invoking it and disable it if it interferes with unrelated work.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The activation phrases are very generic (e.g. 'create skill', 'skill design', 'agent pattern') and can plausibly appear in normal conversation about documentation, planning, or training. That increases the chance of accidental skill invocation, causing the agent to switch behavior unexpectedly or apply templates when the user did not intend to activate this skill.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description is broadly phrased to activate whenever users want to create or optimize skills or need general design guidance. In agent environments that use semantic matching, this can cause over-triggering on ordinary planning or development conversations, leading the agent to load this skill unexpectedly and alter behavior outside the user's intent.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger keywords include ambiguous phrases such as 'create skill', 'skill template', 'skill design', and 'build a skill' without constraints, which can match many benign development discussions. This increases the chance of unintended activation, context pollution, and the agent applying the wrong workflow or loading extra reference material when not appropriate.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases and description are broad enough to activate on many ordinary writing requests, which can cause the skill to be invoked outside its intended scope. Over-broad activation increases the chance of context hijacking, unintended instruction precedence, or generation of templated output when the user wanted a different task, reducing reliability and potentially interfering with safer or more appropriate behaviors.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases in the example SKILL.md are broad and generic (for example, phrases like 'I want to' and 'build a'), which can cause the skill to activate in many unrelated conversations. Unintended invocation can hijack normal agent behavior, force unnecessary multi-turn questioning, and interfere with more appropriate skills or direct responses.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases shown in the template are broad enough to activate on common documentation-related requests, which can cause the skill to engage unexpectedly and steer the interaction into a rigid multi-step workflow. In a broader agent system, overly broad activation increases the chance of inappropriate skill invocation, user confusion, and unintended processing of user content without clear intent to use this specific pipeline.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The SKILL.md template uses broad trigger phrases like 'review this' and 'check code', which can unintentionally match common user requests and activate the skill outside its intended scope. In agent systems, over-broad activation can route sensitive or unrelated content into an auditing workflow, increasing the chance of context confusion, policy bypass-by-misrouting, or unintended handling of user data.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.