Back to skill

Security audit

Work Productivity Agent Browser Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overly broad activation wording, but no hidden execution, credential access, persistence, or destructive behavior.

Install only if you want a general workflow helper for agent-browser-style productivity tasks. Be aware it may activate for generic browser or automation requests, so prefer explicit invocation or tighter trigger settings if your environment supports that.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger sentences are so broad and generic that they can cause the skill to activate for loosely related requests involving browsers, automation, workflows, or productivity. In an agent ecosystem, this increases the chance of unintended invocation, context hijacking, or the skill being selected in situations where its guidance is inappropriate, which can lead to unsafe automation or user confusion.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrases are broad, generic, and partially duplicated from the demand statement, which increases the chance the skill will activate for loosely related requests. In an automation/browser-workflow context, unintended invocation can route users into the wrong workflow, causing inappropriate automation guidance, confusion, or unsafe task execution without clear user intent.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description and usage guidance are broad enough to match common terms like browser, automation, and workflow support, which increases the chance of unintended activation in unrelated contexts. Overbroad activation can route users into the wrong skill, causing inappropriate actions, unsafe assumptions, or reduced reliability in agent behavior.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger keyword list contains highly generic terms such as browser, automation, and cli without contextual qualifiers. In an agent ecosystem, these broad keywords can cause frequent accidental invocation, which may lead to confused task routing or execution of guidance that was not intended for the user's actual request.

Vague Triggers

Low
Confidence
82% confidence
Finding
The example trigger sentences are vague, repetitive, and partially truncated, so they do not teach precise activation boundaries. Poor activation examples can reinforce over-triggering and make it harder for maintainers or routing systems to distinguish intended use from unrelated requests.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger list includes very broad everyday terms such as "browser", "automation", and "cli", which can cause this skill to activate in many unrelated conversations. Over-broad activation increases the chance that the wrong skill takes control of a task, leading to unintended guidance, confused routing, or unsafe application of browser-automation advice outside its intended context.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description defines activation conditions across a very wide set of categories, including general topics like work-productivity, browser, headless, and automation, without clear boundaries. This ambiguity can cause accidental invocation for unrelated requests, expanding the skill's effective scope and increasing the risk of misapplied instructions or workflow interference.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The default prompt uses a very broad natural-language trigger phrase tied to common terms like work-productivity, browser, automation, workflow, checklist, and analysis. This increases the chance of accidental or overly eager skill activation during unrelated conversations, which can route user requests into this skill without clear user intent and expand the skill’s influence over normal agent behavior.

Vague Triggers

Medium
Confidence
97% confidence
Finding
Enabling implicit invocation without tight activation constraints allows the platform to auto-select this skill based on vague semantic matches rather than explicit user choice. In this skill’s context, the broad productivity/browser scope makes that more dangerous because many benign requests could unintentionally trigger the skill, causing confusion, unintended actions, or excessive access to workflows the user did not request.

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger sentence is overly broad and built from common everyday phrasing, which can cause the skill to activate in contexts far beyond its intended scope. In an agent environment, this increases the chance of inappropriate invocation, irrelevant workflow generation, and accidental handling of user requests that were not actually asking for this skill.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger descriptions lack precise activation boundaries, making it unclear when the skill should or should not run. This ambiguity can lead to over-triggering, routing mistakes, and unintended use of browser/automation-oriented guidance in unrelated user requests, which is especially risky for a general productivity skill with broad keywords like 'browser' and 'automation'.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.