Back to skill

Security audit

Work Productivity Agent Browser Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-style workflow helper with overly broad activation wording, but it does not contain hidden code, persistence, credential handling, or destructive behavior.

Install only if you want a lightweight helper for Agent Browser-style workflow planning and reliability checklists. Be aware that its broad keywords and implicit invocation may make it appear for ordinary browser, CLI, automation, or bug-fix requests where a more specific skill would fit better.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrases are broad enough to match common requests about browsers, automation, CLI, or bug fixing, which can cause the skill to activate outside its intended scope. In an agent environment, overbroad invocation can route unrelated user tasks into this workflow, leading to inappropriate automation guidance, unexpected actions, or reduced operator control.

Vague Triggers

High
Confidence
97% confidence
Finding
The skill description is extremely broad and matches generic terms like work-productivity, browser, automation, and analysis, which can cause the skill to activate for many unrelated user requests. Over-broad activation increases the chance of unintended routing, prompt-context pollution, and inappropriate application of this skill’s guidance in situations where a more specific or safer skill should handle the task.

Vague Triggers

High
Confidence
98% confidence
Finding
The keyword list includes ambiguous everyday terms such as browser, automation, cli, and bug fix without constraints, making accidental triggering highly likely. In a skill-routing system, this can hijack ordinary requests and insert irrelevant or risky instructions into downstream handling, reducing reliability and potentially bypassing intended specialization boundaries.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The example trigger sentences largely restate the broad requirement text and do not establish clear activation boundaries, so they reinforce permissive matching behavior rather than clarifying scope. This makes it harder for maintainers and routing logic to distinguish legitimate invocations from normal conversation, increasing misfires and unintended skill selection.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger list includes very generic terms such as 'browser', 'automation', and 'cli', which are likely to appear in many unrelated requests. This can cause unintended activation of the skill, leading the agent to apply the wrong workflow, produce irrelevant automation guidance, or override a more appropriate skill selection path.

Vague Triggers

High
Confidence
91% confidence
Finding
The activation description says to use the skill for broad categories like work-productivity, browser, headless, and automation, which are expansive domains rather than narrowly scoped intents. This increases the chance that the skill is invoked for loosely related tasks, causing misrouting, unsafe assumptions, and workflow confusion in downstream agent behavior.

Natural-Language Policy Violations

Medium
Confidence
83% confidence
Finding
The file is written entirely in Chinese and does not indicate language negotiation or fallback behavior based on user preference. In a multilingual environment, this can degrade usability, cause misunderstanding of instructions, and increase the chance of incorrect execution when the user or orchestrator expects another locale.

Vague Triggers

High
Confidence
95% confidence
Finding
The default prompt contains very broad trigger terms such as work-productivity, browser, headless, automation, checklist, and analysis, and the policy also allows implicit invocation. That combination can cause the skill to activate in many ordinary conversations without clear user intent, increasing the risk of prompt-scope hijacking, unintended tool usage, or accidental execution of workflow guidance in unrelated contexts.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger sentence is broad enough to match common user phrasing rather than a narrowly scoped request for this specific skill. That can cause accidental invocation in unrelated contexts, leading the agent to apply browser-workflow guidance when the user did not intend it, which increases the chance of unsafe or inappropriate automation suggestions.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger scope is ambiguous because it mixes broad productivity terms with a long requirement description, making it unclear when the skill should activate. In an agent environment, ambiguous routing can misfire across many ordinary requests and expose users to unintended automation behavior or irrelevant operational advice.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.