Back to skill

Security audit

Deep Work Orchestrator

Security checks across malware telemetry and agentic risk

Overview

This is a Chinese-language productivity coaching skill for planning focused work, with no code, installs, network access, credentials, or hidden automation.

Safe to install for focus planning. Only share schedule, energy, and distraction details you are comfortable giving to the agent, and use a translated or localized version if you do not read Chinese.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The Usage section is broad enough to trigger on many generic productivity or planning requests, which can cause this skill to activate outside its intended niche. Over-broad activation increases the chance of irrelevant instruction injection into unrelated conversations and can crowd out more appropriate skills, reducing user control and response quality.

Natural-Language Policy Violations

Medium
Confidence
78% confidence
Finding
Presenting the skill entirely in Chinese without a language-choice or opt-in can cause users or orchestrators to invoke content the user may not understand, weakening informed consent and increasing the risk of misapplication. In a routing context, language mismatch can also lead to incorrect activation or poor interpretation of instructions and boundaries.

VirusTotal

No VirusTotal findings

View on VirusTotal

Static analysis

No suspicious patterns detected.