Back to skill

Security audit

Work Productivity Agent Browser Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overly broad activation wording, but it does not run code, request credentials, persist, or send data anywhere.

Before installing, understand that this skill may be selected too often for generic browser or automation requests. It is safest to invoke it explicitly for Agent Browser workflow planning, debugging, reliability hardening, or checklist work, and avoid relying on implicit routing until the trigger wording is narrowed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger sentences are extremely broad and partially templated, making the skill eligible for activation on vague requests involving browser, automation, or workflow help. In an agent ecosystem, overbroad activation can cause the wrong skill to run on unrelated prompts, leading to unintended browser automation guidance, context confusion, or unsafe task execution paths.

Vague Triggers

High
Confidence
88% confidence
Finding
The trigger phrases are extremely broad and include generic terms like browser, automation, cli, and bug fix, which can cause the skill to activate in many unrelated contexts. In an agent environment, over-broad invocation increases the chance the wrong workflow is selected, leading to unintended actions, confused delegation, or unsafe application of browser-automation guidance outside the user's actual intent.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger keywords are extremely broad terms like 'browser', 'automation', and 'cli', which can cause this skill to activate for many unrelated requests. Overbroad activation increases the chance of inappropriate skill selection, context hijacking, or the skill influencing tasks outside its intended scope, reducing safety and predictability.

Vague Triggers

High
Confidence
96% confidence
Finding
The manifest says to use the skill when a user asks for broad categories such as 'work-productivity', 'browser', 'headless', or 'automation', which are common across many benign and unrelated requests. This ambiguous 'use when' language can make the skill eligible in too many contexts, increasing the risk of unintended invocation and interference with more appropriate or safer skills.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The example trigger sentences are truncated and vague, so they do not establish clear semantic boundaries for when the skill should be selected. Poor examples can amplify misrouting by training operators or systems to match partial, generic phrasing rather than the intended narrowly scoped use case.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger list includes broad, everyday terms such as "browser", "automation", and "cli", which can cause the skill to activate in many unrelated conversations. Over-broad auto-activation increases the chance that this skill overrides more appropriate skills or injects workflow guidance where it was not intended, reducing reliability and potentially causing unsafe or irrelevant actions in downstream agent behavior.

Vague Triggers

High
Confidence
94% confidence
Finding
The activation description is overly broad and applies to generic categories like work-productivity, browser, headless, and automation without clear boundaries. This makes accidental invocation likely, especially in mixed-purpose environments, which can misroute user requests and cause the agent to follow an ill-fitting workflow instead of the correct specialized skill.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The default prompt and description use very broad, generic terms like work-productivity, browser, automation, checklist, analysis, and implementation support, which can match many ordinary user requests unrelated to a narrowly scoped skill. This increases the chance of accidental routing or over-invocation, causing the agent to apply this skill in inappropriate contexts and potentially expose users to unintended workflow behavior or misleading assistance.

Vague Triggers

Medium
Confidence
96% confidence
Finding
Enabling implicit invocation without clear trigger constraints allows the platform to auto-select this skill based on loosely matching language, even when the user did not explicitly request it. In combination with the broad wording in the metadata, this can cause persistent overreach, unintended automation guidance, and unpredictable behavior across unrelated conversations.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger sentence is extremely broad and generic, making it likely that unrelated user requests will activate this skill. Over-broad routing can cause the agent to invoke browser-automation or workflow guidance in contexts where it is not appropriate, increasing the chance of unsafe actions, user confusion, or policy bypass through accidental tool selection.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The invocation guidance does not define where this skill should and should not be used, so the agent may route many loosely related productivity or automation requests into it. In a skill that references browser and headless automation, ambiguous activation increases the risk of overreach into sensitive browsing or automation scenarios without sufficient contextual checks.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.