Back to skill

Security audit

Work Productivity Agent Browser Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This skill is a documentation and workflow helper with no executable install behavior, though its broad triggers may cause accidental activation.

Installers should be aware that this skill may be selected for loosely related browser, automation, CLI, or bug-fix prompts. It is best used when the user explicitly wants Agent Browser-style workflow planning, reliability hardening, or adjacent skill design help.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger sentences are broad, repetitive, and partially truncated, which can cause the skill to activate for loosely related prompts such as generic browser, automation, or productivity requests. In an agent ecosystem, overbroad activation can route users into unintended workflows, increasing the chance of unsafe automation guidance, misapplied instructions, or confusion about what the skill is actually designed to do.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrases are broad, generic, and partially templated around common user requests, which can cause the skill to activate when the user did not explicitly intend to invoke it. In an automation/browser workflow context, unintended activation is more concerning because it may steer conversations into browser or headless automation guidance unexpectedly, increasing the chance of inappropriate task execution or user confusion.

Vague Triggers

High
Confidence
97% confidence
Finding
The manifest description includes broad activation terms such as 'browser', 'automation', and 'analysis' that are common across many unrelated user requests. This can cause the skill to activate outside its intended scope, leading to inappropriate routing, reduced user trust, and accidental invocation of browser-oriented workflows in contexts that may involve sensitive actions or misleading automation assistance.

Vague Triggers

High
Confidence
98% confidence
Finding
The trigger keyword list is overly ambiguous, containing generic terms like 'browser', 'cli', 'automation', 'optimized', and 'bug fix' that can match a very large portion of normal assistant traffic. Overbroad triggers materially increase the chance of false activation, which can hijack task selection, interfere with safer or more appropriate skills, and create unsafe automation guidance in contexts where browser tooling was not requested.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example trigger sentences are malformed, truncated, and do not establish clear activation boundaries, making it harder for maintainers and routing systems to infer the intended scope safely. Poorly specified examples reinforce ambiguous activation behavior and can normalize triggering on partial or generic phrases rather than concrete user intent.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger keywords include very broad everyday terms such as 'browser', 'automation', and 'cli', which can cause the skill to be invoked in many unrelated contexts. Over-broad activation increases the chance of routing users into an unintended workflow, producing irrelevant guidance or causing the agent to apply browser-automation patterns where they are not appropriate.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill description defines a very broad scope covering work-productivity, browser, headless, automation, practical workflows, checklists, analysis, and implementation support without clearly stating exclusion boundaries. This makes it easy for the orchestrator to select the skill for loosely related tasks, which can misroute requests and expand the skill's effective authority beyond what users intended.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The default prompt is broad, vague, and phrased in everyday language, which increases the chance the platform will invoke this skill in situations the user did not clearly intend. Because the skill is positioned around general productivity, browser, automation, and implementation help, an ambiguous prompt can cause over-selection and route sensitive or unrelated tasks into a browser-capable workflow, increasing the risk of unintended actions or unsafe assistance.

Vague Triggers

Medium
Confidence
96% confidence
Finding
Enabling implicit invocation without tight trigger conditions allows the skill to be auto-selected for loosely related requests, which is especially risky for a browser/automation-oriented skill. In this context, unintended activation could lead to the agent offering or initiating web workflow guidance, automation steps, or adjacent operational support in contexts where stronger user confirmation and narrower scope are needed.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger sentence is extremely broad and phrased like ordinary user language, which can cause the skill to activate in situations far beyond its intended scope. In an agent environment, overbroad activation can route unrelated requests into browser/headless automation workflows, increasing the chance of unintended actions, confusing outputs, or unsafe automation being suggested when not appropriate.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The invocation guidance does not set firm boundaries for when the skill should or should not be used, so the agent may select it for loosely related productivity or browser requests. Because this skill concerns browser-style workflows and automation, ambiguous routing increases operational risk by encouraging unnecessary automation guidance and reducing the predictability of skill selection.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.