Productivity Helper #2

Security checks across malware telemetry and agentic risk

Overview

This is a simple productivity helper, but it requests broad command and file access and points users to mismatched or external setup sources.

Review before installing. Use this skill only if you are comfortable with broad local command and file permissions, confirm any shell command or file change before it runs, and verify the external setup guide and repository match the exact skill you intend to install.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill’s activation guidance is broad and matches very common productivity-related requests, which increases the chance of unintentional triggering during normal conversation. While the content itself is not overtly harmful, unnecessary activation can expose users to unintended tool use or workflow changes because the skill has Bash, Read, and Write permissions.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The example phrase is nearly indistinguishable from ordinary user speech, so it can act as an accidental trigger for the skill in benign conversations. In this context, the risk is amplified slightly because the skill is permitted to use Bash, Read, and Write, meaning an unintended activation could lead to unnecessary file access or command execution paths.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal