Back to skill

Security audit

Work Productivity Agent Browser Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with broad auto-invocation wording, but no hidden execution, credential access, persistence, or destructive behavior was found.

Install only if you want this helper to be available for Agent Browser-style workflow planning and troubleshooting. Because implicit invocation is enabled and the trigger terms are broad, users should watch for accidental activation on unrelated browser, automation, CLI, or generic bug-fix requests; narrowing triggers would improve predictability.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger sentence is broad and natural-language-like, which can cause the skill to activate in situations beyond the author’s intended scope. In an automation/browser workflow skill, accidental activation is more dangerous because it may steer agent behavior toward operational browser tasks, setup changes, or workflow generation without sufficiently clear user intent.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The invocation guidance lacks precise activation boundaries and mixes broad keywords like 'browser', 'automation', and 'work-productivity' with open-ended trigger text. This increases the chance of misrouting unrelated user requests into this skill, which is especially risky here because the skill is positioned to influence potentially sensitive browser/headless automation workflows.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The trigger phrases are broad, generic, and partially templated, which can cause the skill to activate for loosely related requests such as general browser, automation, or productivity tasks. In an agent workflow, overbroad invocation increases the chance of unintended execution paths, misuse of automation capabilities, or accidental application of this skill in contexts the user did not intend.

Vague Triggers

High
Confidence
97% confidence
Finding
The skill description is broad enough to match many ordinary requests about browsers, automation, workflows, or productivity, which can cause unintended activation. Over-broad invocation increases the chance that this skill is selected in contexts where its guidance is irrelevant, potentially bypassing more appropriate or safer skills and creating prompt-routing confusion.

Vague Triggers

High
Confidence
99% confidence
Finding
The keyword list includes highly generic terms like 'browser', 'automation', 'cli', and 'bug fix', which are common across many unrelated tasks. This makes accidental triggering likely and can cause the agent to apply this skill in inappropriate contexts, degrading reliability and potentially exposing users to incorrect workflow guidance or priority inversion among skills.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The example trigger sentences reinforce vague activation by showing the skill can be invoked from loosely phrased requests that do not establish a clear boundary for when it should apply. This trains or encourages broad matching behavior, making misrouting more likely in multi-skill environments and reducing operator confidence in predictable activation.

Vague Triggers

High
Confidence
92% confidence
Finding
The trigger keywords are extremely broad terms like 'browser', 'automation', 'cli', and 'bug fix', which can match many unrelated user requests and cause the skill to activate outside its intended scope. In an agent system, overbroad activation increases the chance of inappropriate routing, unexpected behavior, or accidental application of workflow guidance in contexts with different safety requirements.

Vague Triggers

High
Confidence
88% confidence
Finding
The description says to use the skill when users ask for broad categories such as work-productivity, browser, headless, or automation, without defining clear inclusion or exclusion criteria. This ambiguity can make the skill capture general requests it was not designed for, leading to misapplication, reduced safety review fidelity, and potentially unsafe assistance in adjacent domains.

Vague Triggers

High
Confidence
94% confidence
Finding
The skill description and default prompt use very broad terms such as work-productivity, browser, automation, checklist, analysis, and implementation support, which are common in ordinary requests and can cause the skill to be invoked outside a narrow, user-intended scope. When paired with implicit invocation, this increases the chance the agent routes general tasks into this skill unexpectedly, exposing users to unintended behavior, prompt injection surface, or workflow side effects.

Vague Triggers

High
Confidence
97% confidence
Finding
Enabling allow_implicit_invocation without strict activation constraints allows the platform to invoke this skill automatically based on loose semantic matches rather than explicit user consent. In this skill, the scope is already broad, so implicit invocation materially raises the risk of unintended tool usage, confused-deputy behavior, and execution of browser-oriented workflows in contexts where the user did not clearly request them.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentences are so generic that they can match routine user requests about browsers, automation, or productivity even when the user did not intend to invoke this specific skill. This creates unintended skill activation risk, which can route conversations into the wrong workflow and potentially expose the model to adversarial or irrelevant instructions embedded in the skill.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.