Back to skill

Security audit

Work Productivity Agent Browser Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a non-executable workflow helper, with a routing-scope issue but no evidence of hidden, destructive, credential-seeking, or persistent behavior.

Install only if you want a general agent-browser workflow helper that may be invoked automatically for broad browser, automation, CLI, or bug-fix requests. Publishers should narrow triggers or disable implicit invocation to reduce accidental activation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger sentences are extremely generic and include broad terms like work-productivity, browser, automation, and practical workflow, which can cause the skill to activate in many unrelated contexts. In an agent ecosystem, overbroad activation can route sensitive or unintended tasks into this skill, increasing the chance of misuse, prompt collisions, or unsafe browser-automation guidance being applied where it was not specifically requested.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are broad, malformed, and weakly scoped, which can cause the skill to activate for unrelated browser, automation, or productivity requests. In an agent environment, overbroad activation can route sensitive or safety-relevant tasks into the wrong workflow, increasing the chance of unintended actions or misleading outputs.

Vague Triggers

High
Confidence
95% confidence
Finding
The skill description advertises activation for very broad terms like "browser," "automation," and "practical workflow," which are common across many unrelated tasks. This can cause the skill to activate outside its intended scope, leading to inappropriate guidance being injected into unrelated conversations and reducing safety and predictability of agent behavior.

Vague Triggers

High
Confidence
98% confidence
Finding
The keyword list includes generic triggers such as "browser," "automation," "cli," and "bug fix" without any scope guards. In a skill-routing system, this makes accidental invocation likely across a wide range of unrelated requests, which can override more appropriate skills and produce misleading or unsafe task handling.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The example trigger sentences are vague and repetitive, and they do not show users or the router what a safe, precise invocation looks like. Poor examples reinforce overbroad matching behavior and make it easier for the skill to be selected in ambiguous contexts where it may not fit the user's actual intent.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger list includes very broad generic terms such as "browser", "automation", and "cli", which can match many unrelated requests and cause the skill to activate outside its intended scope. In an agent system, over-broad invocation increases the chance of unintended workflow injection, irrelevant guidance, or accidental overriding of more appropriate skills.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The description says to use the skill when users ask about broad areas like work-productivity, browser, headless, or automation, but it does not define clear boundaries for when the skill should not be used. This ambiguity can lead to inappropriate routing and unintended application of the skill to requests beyond the validated demand area.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill enables implicit invocation while using a very broad description and default prompt tied to generic terms like productivity, browser, automation, workflow, and implementation support. This can cause the skill to be auto-selected in contexts beyond its intended scope, increasing the chance of unintended prompt injection exposure, overreach into sensitive tasks, or user confusion about which capability is acting.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentence begins with a very broad phrase ('Help me ...'), which can cause the skill to activate for many ordinary user requests that are not actually intended for this workflow. In an agent environment, over-broad activation can route unrelated tasks into browser/automation-oriented behavior, increasing the chance of unintended actions, user confusion, or misuse of adjacent capabilities.

Vague Triggers

Medium
Confidence
91% confidence
Finding
This trigger sentence is too vague to reliably distinguish when the skill should be invoked, because it references a long requirement statement rather than a clear user intent or concrete task. Ambiguous activation criteria are dangerous in agent systems because they increase false-positive routing and may cause automation, analysis, or workflow generation in contexts the user did not intend.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.