Back to skill

Security audit

Work Productivity Agent Browser Workflow Helper

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only workflow helper with broad activation wording, but no executable code, hidden behavior, credential handling, persistence, or data access.

Install this as a low-risk helper if you want general agent-browser workflow guidance. Be aware that its broad trigger wording may make it activate for generic browser, CLI, or automation requests where a more specific skill would be a better fit.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrases are broad, repetitive, and only loosely scoped to the actual capability of the skill, which can cause the skill to activate in contexts the user did not intend. In an agent workflow, ambiguous invocation increases the chance of incorrect tool selection, irrelevant automation, or accidental use in higher-risk browser/headless tasks where safety expectations differ.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are broad enough to match ordinary requests about productivity, browser use, or automation, which can cause the skill to activate outside its intended scope. In an agent ecosystem, overly permissive routing increases the chance of unintended execution, inappropriate tool use, or the skill influencing unrelated workflows without clear user intent.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger list includes very broad terms like "browser," "automation," and "cli," which are common across many unrelated requests. That can cause unintended activation of this skill, leading the agent to apply browser-workflow guidance in contexts where it was not requested, increasing the chance of unsafe or irrelevant actions. In this skill's context, the risk is elevated because it targets automation and headless/browser workflows, which can influence operational behavior.

Vague Triggers

High
Confidence
93% confidence
Finding
The manifest description says to use the skill when a user asks for broad categories like "browser," "headless," "automation," or needs almost any practical artifact or analysis. This creates an overly permissive activation condition that can route many unrelated prompts into this skill, causing mis-scoping, confusing behavior, or inappropriate workflow suggestions. Because the skill is framed as generally applicable workflow support, the ambiguity makes accidental invocation more likely.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger list includes very broad generic terms such as "browser", "automation", and "cli", which can match many unrelated user requests and cause this skill to be invoked outside its intended scope. Over-broad activation increases the chance of inappropriate guidance, prompt-routing errors, and accidental exposure of users to outputs that do not fit their task or risk profile.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The description says the skill should be used when a user asks for broad categories like work-productivity, browser, headless, or automation, but it does not define clear inclusion or exclusion criteria. This ambiguity can lead orchestration systems or users to invoke the skill for loosely related tasks, reducing routing safety and increasing the likelihood of incorrect or overreaching assistance.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill metadata and default prompt are extremely broad and vague, covering many generic tasks like browser, automation, workflow, checklist, analysis, and implementation support. Combined with implicit invocation, this can cause the skill to activate in unintended contexts, increasing the chance that users or upstream agents are steered into using this skill when a narrower, safer skill would be more appropriate.

Vague Triggers

High
Confidence
92% confidence
Finding
The trigger sentence begins with a very broad phrase ('Help me') that can match many unrelated user requests, causing the skill to activate outside its intended browser-workflow scope. Overbroad activation increases the chance that this skill intercepts prompts meant for other tools, leading to unsafe or misleading automation guidance in contexts the skill was not designed to handle.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger description and sample invocations are ambiguous, lengthy, and lack clear boundaries for activation, making it hard to distinguish intended use from ordinary discussion of productivity, automation, or browser topics. This can cause accidental routing to the skill and broaden its operational surface area, which is especially risky for an agent-oriented workflow helper that may influence automation behavior or implementation choices.

Static analysis

No suspicious patterns detected.