Back to skill

Security audit

Work Productivity Agent Browser Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with no executable code, but its automatic activation wording is broader than ideal.

Installers should be aware that this skill may activate for general browser or automation requests because its triggers are broad. Review or narrow the trigger terms if precise skill routing matters in your environment.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger phrases are broad, repetitive, and partially generic, which can cause the skill to activate for loosely related prompts involving browsers, automation, or workflow help. In an agent ecosystem, unintended invocation can route user requests into the wrong workflow, increasing the chance of unsafe automation, confusion, or execution under incorrect assumptions.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases are broad and generic enough that ordinary user requests about browser workflows, practical workflows, or automation could unintentionally invoke this skill. Over-broad activation increases the chance of the agent applying the wrong workflow or exposing capabilities in contexts the user did not explicitly request, which is a genuine security and reliability concern for agent skills.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger list is overly broad and includes generic terms like "browser," "automation," and "cli," which can cause this skill to activate for many unrelated requests. That increases the chance of accidental routing, inappropriate application of the skill, and user confusion, especially in environments where skills are auto-selected from keyword matches.

Vague Triggers

High
Confidence
93% confidence
Finding
The invocation description says to use the skill whenever a user asks for broad categories such as work-productivity, browser, headless, or automation, which are common across many unrelated tasks. This ambiguity can lead to unintended activation and overbroad delegation, making the system less predictable and increasing the risk that an irrelevant or less-safe skill is chosen.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger list includes very common terms such as "browser", "automation", "cli", and "bug fix", which can match many unrelated requests and cause unintended skill activation. Over-broad invocation increases the chance that the skill is selected in contexts it was not designed for, leading to irrelevant guidance, confusion, or unsafe workflow suggestions being applied to the wrong task.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The activation description allows use for broad categories like work-productivity, browser, headless, and automation, without clearly defining scope limits. This ambiguity can cause the skill to be invoked for many loosely related requests, reducing routing precision and potentially exposing users to mismatched operational advice in contexts where different safety or reliability constraints apply.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The default prompt is broad and generic enough that ordinary user language about productivity, browser workflows, or automation could unintentionally trigger this skill. That increases the chance of silent prompt injection into unrelated conversations, causing unexpected agent behavior, scope creep, or execution of workflow logic the user did not explicitly request.

Vague Triggers

Medium
Confidence
94% confidence
Finding
Enabling implicit invocation without strict trigger constraints allows the platform to auto-select this skill based on vague semantic similarity rather than clear user intent. In a browser-automation or workflow-helper context, that is riskier because unintended activation could cause the agent to propose or initiate actions affecting browsing, automation, or work-productivity flows without sufficiently explicit consent.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentence is so broad and awkwardly phrased that it could match ordinary user requests unrelated to the intended skill, causing unintended invocation. In an agent ecosystem, overbroad activation can route user input into the wrong workflow, leading to confusing behavior, incorrect automation, or accidental execution of browser-oriented steps in contexts where they were not requested.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger description and usage signals lack precise scope, mixing broad terms like 'browser', 'automation', and generic help phrases with little disambiguation. This increases the chance that the skill is selected for loosely related prompts, which can create misfires, degrade reliability, and expose downstream workflows to unintended inputs or actions.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.