Productivity Operating System

Security checks across malware telemetry and agentic risk

Overview

This appears to be a normal productivity-planning skill that may ask about personal routines but does not show hidden access, exfiltration, or unsafe actions.

Before installing, be aware that generic requests like planning your day or week may invoke this skill. Avoid sharing sensitive calendar, health, or workplace details unless you are comfortable using them for productivity coaching.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill exposes very broad natural-language triggers such as 'Plan my day', 'What should I work on?', and 'Help me plan next week', which overlap heavily with ordinary assistant interactions. This can cause unintended routing into the skill when users did not explicitly choose it, leading to surprising behavior, incorrect task framing, or interference with other skills and system policies.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal