Back to skill

Security audit

Work Productivity Agent Browser Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a guidance-only workflow skill with overly broad activation wording, but it does not request sensitive access or run code.

This skill appears safe to install as a lightweight workflow helper, but its activation wording is loose. Prefer invoking it explicitly by name, and review outputs carefully if it appears during unrelated browser, automation, CLI, or bug-fix tasks.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger sentences are broad, repetitive, and loosely scoped, which can cause the skill to be invoked in situations beyond the author’s intended use. In an automation/browser-workflow context, overbroad invocation increases the chance that the agent applies browser or workflow guidance to sensitive tasks without sufficient user confirmation or task-specific safeguards.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are broad enough to match ordinary requests about browsers, automation, or productivity, which can cause the skill to activate when the user did not explicitly intend it. In an agent/browser workflow context, unintended invocation can steer execution into automation-oriented behavior, increasing the chance of inappropriate actions, confusion, or unsafe task handling.

Vague Triggers

High
Confidence
95% confidence
Finding
The skill description and usage guidance use very broad activation language, including generic domains like browser, automation, and work-productivity, without clear scoping constraints. This can cause the skill to activate in unrelated contexts, increasing the chance that users receive unintended workflows or automation guidance that bypasses more appropriate, specialized, or safer skills.

Vague Triggers

High
Confidence
98% confidence
Finding
The trigger keywords include highly generic terms such as browser, automation, cli, and bug fix, which are common across many unrelated tasks. In a routing or auto-invocation system, these broad keywords can lead to frequent unintended activation, misrouting user requests and potentially surfacing automation-oriented guidance in contexts where it is not appropriate.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example trigger sentences are vague, truncated, and do not clearly define what distinguishes an intended invocation from an accidental match. Poorly bounded examples make it easier for downstream systems or authors to overgeneralize activation logic, increasing accidental use of the skill in irrelevant situations.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger list is very broad and includes generic terms like "browser", "automation", "cli", and "bug fix", which can cause this skill to activate for many unrelated requests. Overbroad activation increases the chance of misrouting user tasks, unintended invocation, and accidental exposure of the skill's instructions or workflows in contexts where they do not belong.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The default invocation prompt contains very broad, everyday-language terms such as "help me" and generic workflow-related wording, which can cause unintended or implicit activation outside the author's intended scope. Because implicit invocation is enabled, this increases the chance that unrelated user requests trigger the skill, expanding exposure and creating opportunities for prompt-surface abuse or accidental execution in inappropriate contexts.

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger sentence begins with a very broad everyday phrase ('Help me'), which can cause the skill to activate for many unrelated requests. In a routing or auto-invocation system, this increases the chance of accidental invocation, misclassification, and unsafe cross-context assistance beyond the intended browser-workflow scope.

Vague Triggers

Medium
Confidence
88% confidence
Finding
Although this trigger includes slightly more context, it still starts with a broadly reusable phrase ('I need a practical workflow for') and then appends requirement text that is not a precise user intent. This can still match unrelated productivity requests and cause overbroad skill selection, especially in systems that rely on fuzzy keyword or sentence matching.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.