Back to skill

Security audit

Work Productivity Agent Browser Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-style workflow helper with broad activation wording but no evidence of hidden execution, credential access, persistence, or destructive behavior.

Before installing, understand that this skill may activate for general browser, automation, or bug-fix requests because its triggers are broad. It appears safe as a guidance-only helper, but users should confirm it is the intended skill when working on unrelated browser or automation tasks.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger sentences are broad enough that the skill may activate for loosely related requests involving browsers, automation, or workflows, rather than only for the intended constrained use case. In an agent ecosystem, overly permissive activation can cause the wrong skill to take control of a task, leading to unintended actions, confused delegation, or unsafe workflow guidance in contexts the skill was not designed to handle.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrases are broad, generic, and partially natural-language prompts, which increases the chance of unintended skill invocation during ordinary user conversations. In an automation/browser-oriented skill, accidental activation can lead to confusing behavior, unexpected workflow execution, or unnecessary access to browser/automation capabilities even without explicit user intent.

Vague Triggers

High
Confidence
96% confidence
Finding
The skill description and activation guidance are broad enough to match many ordinary requests involving browsers, automation, or productivity, which can cause the skill to be invoked outside its intended scope. Over-broad routing increases the chance that unrelated user tasks are handled by this skill, creating prompt-scope confusion and making downstream unsafe or irrelevant instructions more likely to influence behavior.

Vague Triggers

High
Confidence
98% confidence
Finding
The keyword list includes vague, high-frequency terms such as 'browser', 'automation', 'cli', and 'bug fix' without scope constraints, so many unrelated requests may accidentally activate the skill. In a skill-routing system, this can cause excessive interception of general tasks and reduce trust boundaries between specialized skills.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The example trigger sentences are malformed and ambiguous, which weakens trigger specificity and may train maintainers or routing logic toward incorrect activation patterns. While not directly exploit code, poor examples can broaden unintended invocation and make misclassification more likely in production use.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger keyword list includes highly generic terms such as "browser", "automation", and "cli", which can match many unrelated user requests and cause the skill to activate outside its intended scope. Over-broad activation increases the chance of context hijacking, incorrect tool selection, and unintended delegation to a workflow that may shape responses in ways the user did not request.

Vague Triggers

High
Confidence
97% confidence
Finding
The manifest description defines usage in very broad, ambiguous terms, covering multiple common categories like work-productivity, browser, headless, and automation, plus any request for a workflow, checklist, analysis, or implementation support. This creates a large activation surface where ordinary requests may invoke the skill unintentionally, leading to misrouting, prompt-scope overreach, and possible interference with more appropriate or safer skills.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example trigger phrases are vague and closely resemble normal help requests, which trains or encourages routing systems to treat everyday language as sufficient to invoke this skill. This broad overlap can produce false activations, causing the assistant to apply the wrong workflow or expose users to unnecessary automation-oriented behavior when they asked for general assistance.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The default prompt is framed as a very broad invocation phrase and the policy also permits implicit invocation, which can cause the skill to activate in contexts only loosely related to the user's intent. In an agent/browser workflow helper, this increases the chance of unintended execution, prompt-surface expansion, and accidental routing of sensitive or unrelated tasks into a skill with automation-oriented capabilities.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentence is extremely broad and malformed, beginning with generic language like 'Help me' and embedding a long requirement description. This can cause accidental activation on ordinary user requests, expanding the skill's execution scope beyond clearly intended use and potentially routing unrelated tasks through automation-oriented behavior.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger examples are ambiguous, truncated, and malformed, so the activation criteria are unclear. Unclear triggers increase the chance of misrouting, accidental invocation, or abuse by crafting prompts that loosely resemble the examples, which is especially risky for a workflow helper associated with browser/headless automation.

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.