Back to skill

Security audit

Work Productivity Agent Browser Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper; its activation terms are broad, but it does not install code, persist, access secrets, or run automation by itself.

Installers should know this skill may activate for general browser, automation, CLI, or bug-fix requests more often than intended. Use it when you specifically want agent-browser workflow help, and prefer narrower triggers in a future revision.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger sentences are broad and partially generic, which can cause the skill to activate for loosely related user requests rather than explicit intent to use this workflow. In an agent ecosystem, overbroad triggers can misroute tasks, override more appropriate skills, and increase the chance that browser or automation-oriented behavior is invoked in contexts the user did not intend.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrases are broad enough to match many ordinary user requests about browsers, automation, workflows, or productivity, which can cause the skill to activate outside its intended scope. In an agent environment, overbroad invocation increases the chance of inappropriate tool use, unexpected workflow execution, or routing users into automation flows they did not explicitly request.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The manifest description includes very broad activation terms like 'browser', 'automation', and 'work-productivity' that can match many unrelated user requests. This can cause the skill to be invoked outside its intended scope, increasing the chance of unintended prompt/context injection into ordinary workflows and reducing the reliability of skill routing.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger keyword list contains several high-collision terms such as 'browser', 'automation', 'cli', and 'bug fix' without qualifiers. In systems that auto-select skills based on keyword overlap, these vague triggers can lead to over-activation, causing this skill to intercept unrelated tasks and potentially influence outputs in contexts where it was not requested.

Vague Triggers

Low
Confidence
84% confidence
Finding
The example trigger sentences are ambiguous and mostly restate broad demand text instead of clearly defining valid invocation boundaries. This weakens routing precision and may train or signal downstream selection logic to activate the skill on loosely related requests, increasing misfires rather than directly enabling code execution or data theft.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger list includes very broad terms such as 'browser', 'automation', and 'cli', which overlap with common everyday requests. This can cause unintended activation of the skill in unrelated contexts, leading the agent to apply the wrong workflow, expose irrelevant capabilities, or override a more appropriate specialized skill.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill description says to use the skill for broad categories like work-productivity, browser, headless, and automation without defining clear boundaries or non-applicable cases. In agent routing systems, this overbroad scope increases the chance of misrouting requests, causing unsafe or low-quality task handling when the skill is invoked outside its intended domain.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The default prompt uses a very broad trigger phrase tied to common terms like work-productivity, browser, automation, and practical help, while the policy also allows implicit invocation. This increases the chance the skill is activated in contexts the user did not specifically intend, which can cause prompt injection exposure, incorrect tool routing, or unintended execution of browser-oriented workflows.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger examples are broad, natural-language phrases that can match ordinary user requests unrelated to this specific skill, increasing the chance of unintended activation. In an agent system, overbroad activation can route users into the wrong workflow, cause prompt/skill confusion, and make downstream behavior less predictable or easier to manipulate via ambiguous phrasing.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The activation guidance does not define strong boundaries for when the skill should or should not be used, and the listed keywords span very generic terms like 'browser', 'automation', and 'cli'. That makes the skill more likely to activate outside its intended domain, which can degrade safety controls, bypass more appropriate specialized skills, or create prompt-routing ambiguity attackers can exploit.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.