Back to skill

Security audit

Work Productivity Agent Browser Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-style workflow helper with some overbroad activation wording, but no hidden execution, persistence, credential access, or data-exfiltration behavior was found.

Installers should be aware that this skill may activate for generic browser or automation requests; prefer explicit invocation when using it, and maintainers should narrow its trigger terms, but the inspected artifacts do not show malicious or high-impact behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger sentences are broad natural-language phrases that resemble ordinary user requests rather than narrowly scoped invocation patterns. This can cause accidental skill activation in unrelated conversations, leading the agent to apply browser/automation workflow behavior when the user did not explicitly intend to invoke this skill.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases are broad enough to match many ordinary productivity, browser, or automation requests, which can cause the skill to activate outside its intended scope. In an agent environment, overbroad routing can lead to inappropriate workflow execution, confused task handling, or accidental exposure of capabilities where the user did not explicitly request this skill.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger keyword list is overly broad and includes common terms like "browser," "automation," and "cli," which can cause the skill to activate for many unrelated requests. In an agent environment, this increases the chance of incorrect routing or unsolicited invocation, potentially leading the model to apply this skill in contexts the user did not intend.

Vague Triggers

High
Confidence
94% confidence
Finding
The manifest description defines activation using broad everyday phrasing such as "browser," "automation," and requests for a "practical workflow, artifact, checklist, analysis, or implementation support." This makes the skill eligible for many normal productivity requests, which can produce accidental activation and unsafe overreach in agent selection.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The example trigger sentences are vague and generic, and they repeat broad request forms like "Help me" and "I need a practical workflow" without clear disambiguation. This trains invocation around common language patterns instead of explicit intent, increasing the risk that unrelated user requests will match this skill.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger keywords are very broad, including generic terms like "browser", "automation", and "cli", which can overlap with many ordinary user requests. This can cause the skill to activate outside its intended scope, leading to incorrect routing, unintended behavior, or overbroad access to workflows that were not requested.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The usage condition in the skill description is vague and covers a wide range of loosely related requests, making it unclear when the skill should or should not be used. Ambiguous scope increases the chance of mis-triggering and applying this skill to tasks beyond its intended safety and operational boundaries.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The default prompt is overly broad and phrased in common language, which increases the chance of unintended or implicit invocation for loosely related user requests. Combined with `allow_implicit_invocation: true`, this can cause the skill to activate outside a narrowly intended scope, exposing users to unexpected automation behavior or unsafe task routing.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentence is overly broad and can cause the skill to activate on generic user requests that merely contain common phrases like 'Help me'. In an agent system, this can lead to incorrect routing, unintended invocation, and increased exposure to the skill's instructions in contexts where it was not actually requested.

Vague Triggers

Medium
Confidence
93% confidence
Finding
This trigger is ambiguous and broad enough to match many unrelated requests, making reliable skill selection difficult. In multi-skill environments, that can cause misfires, prompt confusion, and accidental execution of a workflow that is not appropriate for the user's actual task.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.