Back to skill

Security audit

Work Productivity Agent Browser Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-style workflow helper with no executable code or data access, though its automatic trigger wording is too broad and should be tightened.

Install only if you want an Agent Browser workflow planning helper. Be aware it may activate on ordinary browser or automation wording because implicit invocation is enabled and the trigger examples are broad; narrowing triggers to explicit Agent Browser workflow requests would improve routing safety.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger sentences use generic, everyday phrasing such as 'Help me' and 'I need a practical workflow', which can cause the skill to activate when the user did not specifically intend to invoke it. In an agent environment, overly broad activation increases the chance of accidental routing, unexpected execution paths, and misuse of browser/automation-oriented capabilities.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The README presents trigger sentences and keywords without clear boundaries on when the skill should be invoked, making activation ambiguous. Because this skill is positioned for browser, headless, and automation workflows, accidental invocation is more dangerous than in a passive skill: it may lead to unintended workflow execution, broader tool use, or user confusion about why automation behavior was selected.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger phrases are broad, repetitive, and partially truncated, which can cause the skill to activate for loosely related requests such as generic browser, automation, or productivity tasks. In an agent environment, overbroad activation can misroute user prompts, invoke the wrong workflow, and increase the chance of unsafe or unintended browser automation behavior.

Vague Triggers

High
Confidence
94% confidence
Finding
The skill description includes very broad activation terms such as "browser," "automation," and "work-productivity," which can match many ordinary requests unrelated to this specific workflow. Overbroad routing can cause the wrong skill to activate, leading to unintended behavior, scope confusion, and reduced safety controls when users did not explicitly request this capability.

Vague Triggers

High
Confidence
97% confidence
Finding
The keyword list is composed largely of ambiguous generic terms like "browser," "automation," "cli," and "bug fix," which are common across many unrelated tasks. In a skill-routing system, this can capture a wide range of benign user prompts and invoke this skill inappropriately, increasing the chance of unsafe or incorrect assistance and interfering with intended skill selection.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The example trigger sentences are vague and effectively restate the broad requirement text rather than defining precise activation boundaries. This makes it harder for maintainers and routing systems to distinguish valid invocations from ordinary requests, reinforcing over-triggering and misapplication of the skill.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger keywords include very broad everyday terms such as 'browser', 'automation', 'cli', and 'bug fix', which can cause the skill to activate in many unrelated conversations. Over-triggering can route users into the wrong workflow, leading to unintended instruction injection into unrelated tasks or reduced safety due to context confusion.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill description defines activation conditions with a wide set of loosely bounded topics, including general terms like work-productivity, browser, and automation. This ambiguity increases the chance of accidental invocation, which can misapply the skill in contexts it was not designed for and degrade reliability or safety controls.

Vague Triggers

High
Confidence
90% confidence
Finding
The default prompt is overly broad and uses generic everyday-language guidance, which can cause the platform to invoke this skill in situations only loosely related to the user's request. Because the skill is framed as applicable to many common tasks such as browser, automation, workflow, checklist, and analysis support, it increases the chance of unintentional activation and over-collection or over-execution in the wrong context.

Vague Triggers

High
Confidence
95% confidence
Finding
Enabling implicit invocation without strong trigger constraints allows the system to activate this skill automatically based on ambiguous user intent. In a browser-workflow or automation context, accidental activation is more dangerous because the skill may influence actions, data handling, or navigation behavior without sufficiently explicit user direction.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger sentence begins with an extremely broad everyday phrase ('Help me'), which can cause the skill to activate for many unrelated requests. In an agent workflow context, over-broad invocation increases the chance of unintended routing, causing the agent to apply browser-automation-oriented guidance in contexts the user did not intend.

Vague Triggers

Medium
Confidence
89% confidence
Finding
Although the prefix is slightly more specific ('I need a practical workflow for'), the trigger still remains ambiguous because it can match a wide range of ordinary productivity requests unrelated to this skill. In a skill-selection system, this ambiguity can misroute user requests and cause inappropriate or overly powerful browser-workflow guidance to be applied.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.