Back to skill

Security audit

Work Productivity Agent Browser Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-style workflow helper with overly broad activation wording, but it does not install code, request credentials, persist itself, or perform hidden actions.

Before installing, be aware that this skill may activate for ordinary browser, automation, CLI, or bug-fix requests because its trigger wording is loose. It appears safe as a guidance-only helper, but users should invoke it deliberately for Agent Browser workflow planning or hardening rather than relying on automatic routing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (13)

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger sentence is extremely broad and malformed, making accidental invocation more likely during ordinary discussion of browser workflows or productivity needs. In an agent ecosystem, unintended skill activation can route user requests into an unexpected workflow, causing incorrect automation behavior, wasted actions, or unsafe tool use if the skill later performs browser or headless tasks.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The activation examples are ambiguous because they match common help-seeking language rather than a clearly bounded request for this specific skill. Given this skill targets browser/headless/automation workflows, accidental activation is more concerning than for a passive documentation skill because it could initiate or recommend automation in the wrong context.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases are broad, generic, and partially templated, which can cause the skill to activate for loosely related requests such as general browser, automation, or productivity tasks. In an agent setting, over-broad activation increases the chance of unintended workflow execution, confusing task routing, and unsafe application of browser automation guidance outside the user's actual intent.

Vague Triggers

High
Confidence
97% confidence
Finding
The manifest description includes broad activation terms such as work-productivity, browser, headless, automation, and practical workflow support, which are common across many unrelated user requests. This can cause the skill to activate outside its intended scope, leading to inappropriate routing, overbroad instruction injection, and reduced reliability of downstream agent behavior.

Vague Triggers

High
Confidence
99% confidence
Finding
The trigger keyword list contains highly generic, high-collision words like browser, automation, cli, and bug fix without qualifiers. In a skill-selection system, these terms are likely to match a large volume of benign requests, causing this skill to activate unexpectedly and potentially override more appropriate, narrower skills.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The example trigger sentences are truncated, unnatural, and fail to define realistic boundaries for when the skill should be invoked. Poor trigger examples make accidental activation more likely because they do not teach the orchestrator or maintainers what a properly scoped request looks like versus a generic browser or productivity request.

Vague Triggers

Medium
Confidence
89% confidence
Finding
触发关键词包含 browser、automation、cli、bug fix 等高度通用词,容易与大量普通技术或效率类对话重叠,导致技能在非预期场景被自动调用。误触发本身不一定直接造成越权,但会扩大该技能影响面,使其在不合适上下文中输出自动化建议、代码修改或流程指令,从而增加误操作和后续安全风险。

Vague Triggers

Medium
Confidence
84% confidence
Finding
技能描述将适用范围定义为 work-productivity、agent-browser、browser、headless、automation 及“需要实用流程、产物、检查清单、分析或实现支持”这类宽泛条件,边界明显不足。这样的描述会让路由器或调用者难以区分该技能与其他通用工程/自动化技能的职责,增加误选、过度授权和不恰当建议落地的概率。

Vague Triggers

Low
Confidence
78% confidence
Finding
示例触发句几乎只是复述需求文本,且缺少可操作的、高区分度的触发模式,无法为实际调用提供有效约束。结果是实现方可能退回到依赖宽泛关键词进行匹配,进一步放大误触发和错误路由问题。

Vague Triggers

Medium
Confidence
87% confidence
Finding
The default prompt and description use very broad, generic help-seeking language tied to common terms like browser, automation, workflow, checklist, analysis, and implementation support. This can cause the skill to be selected in situations beyond its intended scope, increasing the chance of prompt/skill hijacking, user confusion, or unsafe delegation to a more privileged browser-capable workflow.

Vague Triggers

Medium
Confidence
93% confidence
Finding
Enabling implicit invocation without clear trigger constraints allows the platform to auto-select this skill based on loosely matching requests. Because this skill is associated with browser-style workflows and automation, unintended activation could expose browsing or automation capabilities in contexts where they were not deliberately requested, increasing the risk of overreach and unsafe actions.

Vague Triggers

High
Confidence
91% confidence
Finding
The trigger sentence is so broad and malformed that it can match ordinary user requests unrelated to this skill's intended scope. In an agent routing system, overly generic triggers can cause the wrong skill to activate, creating prompt-surface expansion and increasing the chance that unrelated tasks are handled with inappropriate assumptions or unsafe workflow guidance.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The description is ambiguous and insufficiently scoped, so the skill may be invoked for vague 'practical workflow' requests without confirming that the task truly concerns agent-browser or headless automation. This increases the risk of misrouting, unintended execution paths, and user confusion, especially because the skill claims broad applicability across work-productivity, browser, headless, and automation contexts.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.