Back to skill

Security audit

Work Productivity Agent Browser Workflow Helper

Security checks for vulnerabilities and agentic risk

Overview

The available evidence shows an ordinary workflow/browser-automation guidance skill with overly broad activation wording, but no verified hidden, destructive, or data-exfiltrating behavior.

Install only if you want broad browser/workflow automation assistance. Be aware it may be selected for loosely related requests because its trigger language is broad; invoke it explicitly for browser or automation tasks and review any proposed browser, CLI, or account-affecting actions before approving them.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger sentences are broad, repetitive, and partially generic, making accidental invocation more likely when users mention common terms like browser, automation, or practical workflow support. In an agent skill ecosystem, unintended activation can cause the wrong workflow to take over a task, leading to unsafe assumptions, irrelevant automation guidance, or execution in contexts the user did not intend.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrases are broad and natural-language-like, such as 'Help me...' and 'I need a practical workflow...', which can match many ordinary user requests unrelated to this specific skill. In an agent ecosystem, this can cause unintended skill activation, leading to incorrect tool selection, workflow confusion, or the application of browser/headless automation guidance in contexts where it was not explicitly requested.

Vague Triggers

High
Confidence
95% confidence
Finding
The skill description is broad enough to match many ordinary user requests about browsers, automation, workflows, or productivity, which can cause the skill to activate outside its intended scope. Over-broad activation increases the chance of prompt-space interference, accidental routing, and application of this skill's instructions in unrelated contexts.

Vague Triggers

High
Confidence
97% confidence
Finding
The keyword list includes generic terms like "browser," "automation," "cli," and "bug fix," which are high-collision triggers that commonly appear in benign, unrelated requests. This makes unintended invocation likely and can let the skill intercept broad categories of user tasks, reducing routing integrity and potentially overriding more appropriate specialized skills.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The example trigger sentences are incomplete and do not establish clear invocation boundaries, so they provide weak guidance for safe, deterministic routing. Ambiguous examples reinforce overmatching behavior and make it easier for unrelated prompts to resemble valid invocations.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger keywords include very broad, common terms such as "browser", "automation", and "cli", which can cause the skill to activate in many unrelated conversations. Over-broad activation increases the chance that the agent applies this skill out of context, potentially steering outputs, exposing internal workflow assumptions, or interfering with safer/more appropriate skills.

Vague Triggers

High
Confidence
95% confidence
Finding
The skill description defines applicability across a wide set of topics and output types without clear boundaries or exclusions. This makes accidental invocation more likely and can cause the skill to influence tasks beyond its intended scope, reducing predictability and creating prompt-routing risk in multi-skill environments.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The default prompt includes a very broad natural-language trigger phrase tied to common terms like work-productivity, browser, automation, and workflow support, while the policy also allows implicit invocation. This can cause the skill to activate in loosely related conversations without clear user intent, increasing the chance that untrusted skill instructions influence responses unexpectedly.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentence is extremely broad and uses common everyday phrasing such as 'Help me' and 'I need', which can cause the skill to activate for many unrelated requests. In an agent environment, overbroad activation can route user tasks into the wrong workflow, causing unintended browser or automation-oriented assistance to be applied where it was not explicitly requested.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The invocation description and trigger section do not clearly constrain when the skill should be used, instead combining broad keywords and generic trigger templates with a long requirement statement. This increases the risk of accidental or excessive invocation, which can misroute tasks, confuse downstream agents, and expand the operational surface for a browser-oriented skill beyond its intended use.

Static analysis

No suspicious patterns detected.