Back to skill

Security audit

Work Productivity Agent Browser Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a low-risk workflow/documentation skill, with the main caveat that its activation wording is overly broad.

Before installing, be aware that this skill may activate more often than intended because it uses generic terms like browser, automation, CLI, and bug fix. It appears safe as a documentation/workflow helper, but the publisher should narrow the trigger wording or disable implicit invocation to avoid irrelevant routing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrases are extremely generic and include broad terms like browser, automation, and practical workflow, which can cause the skill to activate for many unrelated requests. In an agent ecosystem, overbroad activation can route users into unintended workflows, increasing the chance of unsafe automation guidance, user confusion, or accidental execution in contexts the skill was not designed to handle.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrases are broad and partially templated, covering generic terms like browser, automation, and workflow helper language that could cause the skill to activate outside its intended scope. In an agent system, overbroad invocation can lead to inappropriate tool selection, confused delegation, or unintended execution paths, which becomes more concerning because this skill is positioned for browser/headless automation workflows.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger list is overly broad, including generic terms like 'browser', 'automation', 'cli', and 'bug fix' that commonly appear in unrelated requests. This can cause the skill to activate outside its intended scope, increasing the chance of accidental routing, interference with other skills, and unsafe application of browser-automation guidance in contexts where it was not requested.

Vague Triggers

High
Confidence
94% confidence
Finding
The manifest description is ambiguous and expansive, covering broad categories like 'work-productivity', 'browser', 'headless', 'automation', and 'implementation support'. Such vague invocation criteria can cause the system to select this skill for many ordinary tasks, creating prompt-routing confusion and potentially exposing users to irrelevant or risky automation instructions without clear need.

Vague Triggers

High
Confidence
93% confidence
Finding
触发关键词包含 `browser`、`automation`、`cli`、`optimized`、`tree`、`bug fix` 等高度常见或语义宽泛的词,会让该技能在大量无关上下文中被意外激活。误触发会扩大技能适用范围,使其在并不适合的请求中介入,带来错误自动化、越权工作流建议或覆盖更合适技能的风险。

Vague Triggers

Medium
Confidence
89% confidence
Finding
技能描述将适用场景扩展到 `work-productivity`、`browser`、`automation` 等非常宽泛的类别,边界不清,容易覆盖大量普通请求。这样的范围膨胀会导致路由选择失准,使技能在非目标场景下产出不恰当建议,尤其当其涉及自动化、浏览器或执行流程时,误用风险更高。

Vague Triggers

Medium
Confidence
92% confidence
Finding
The default prompt and description use broad, generic terms such as work-productivity, browser, automation, checklist, analysis, and implementation support without narrowly constraining when the skill should activate. This can cause unintended routing or over-invocation in normal user requests, increasing the chance that the agent applies the skill in contexts the user did not explicitly intend, which may lead to unsafe automation guidance or irrelevant privileged behavior.

Vague Triggers

Medium
Confidence
95% confidence
Finding
Enabling implicit invocation while the skill description remains broad makes automatic activation especially risky. A loosely scoped skill that can activate without explicit user selection may intercept unrelated requests and introduce unintended browser automation, setup guidance, or workflow actions in contexts where a safer or more specific skill should have been used.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentence is so broad and awkwardly truncated that it could match loosely related user requests and activate the skill outside its intended scope. Over-broad activation increases the chance of inappropriate routing, causing the agent to apply browser-workflow guidance when the user asked for something more general or unrelated.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The activation examples do not clearly define where this skill should and should not apply, and they reuse long requirement text rather than realistic bounded user intents. This ambiguity can cause accidental invocation, misrouting, or over-application of the skill in ordinary productivity or browser-related conversations.

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.