Back to skill

Security audit

Work Productivity Agent Browser Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overly broad activation wording, but it does not install code, persist, collect data, or request privileged access.

Install only if you want a general Agent Browser workflow helper. Be aware it may activate for broad browser or automation requests because implicit invocation is enabled and the trigger keywords are loose; narrowing those triggers would improve predictability.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger sentences are broad, natural-language phrases that could match ordinary user requests and cause the skill to activate unintentionally. In a browser/headless automation context, accidental invocation is more dangerous because the skill may steer users into automation workflows, produce misleading actions, or increase exposure to risky downstream instructions without the user explicitly selecting this skill.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases are broad enough to activate this skill for generic terms like 'browser', 'automation', or 'bug fix', which can cause unintended invocation outside the intended Agent Browser workflow context. In an agent ecosystem, overbroad activation can route unrelated user requests into a workflow that may produce misleading, unsafe, or unnecessary operational guidance, increasing the chance of misuse or prompt-scope confusion.

Vague Triggers

High
Confidence
95% confidence
Finding
The skill description and usage criteria are broad enough to match many common requests involving browsers, automation, workflows, or implementation help, which can cause the skill to be invoked outside its intended niche. Over-broad invocation increases the chance that an unrelated task receives mismatched guidance or unsafe automation patterns, especially in contexts involving browser control or headless workflows.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger keywords include vague, high-frequency terms such as "browser," "automation," "cli," and "bug fix" without contextual constraints, making accidental invocation likely. In an agent environment, this can route many unrelated tasks through this skill, causing inappropriate actions, confused task selection, or unnecessary exposure to browser-automation guidance in contexts where it does not belong.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger keywords are very broad (`browser`, `automation`, `cli`, `bug fix`) and overlap with many normal user requests, which can cause this skill to activate unintentionally outside its intended scope. In an agent system, overbroad activation can route unrelated tasks into this workflow, leading to unsafe assumptions, irrelevant automation guidance, or interference with more appropriate skills.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The invocation description is broad enough to cover many generic productivity and browser-related requests, making the activation boundary unclear. This increases the chance of accidental invocation and misrouting, especially in ecosystems where skills are selected automatically based on loose semantic matching.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The default prompt contains a very broad invocation phrase tied to common terms like work-productivity, browser, automation, workflow, checklist, and analysis. This increases the chance of unintentional activation in ordinary user conversations, causing the skill to inject its prompt and influence the agent when the user did not explicitly request it.

Vague Triggers

Medium
Confidence
96% confidence
Finding
Implicit invocation is enabled without any visible guardrails, constraints, or exclusions, so the skill may auto-activate across a wide range of unrelated requests. In combination with the broad skill description and default prompt, this creates prompt-routing risk, where the agent may unnecessarily apply browser-workflow behavior or instructions in contexts the user did not intend.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger sentence is so broad and generic that it can cause the skill to activate for ordinary requests that merely mention common workflow or help-oriented language. In an agent setting, overbroad activation increases the chance of unintended routing, confusing task substitution, or the skill being applied in contexts the user did not explicitly request.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The invocation guidance lacks clear boundaries for when the skill should and should not run, which can make dispatch logic overly permissive. This is dangerous because broad matching can cause accidental invocation on unrelated user prompts, leading to incorrect automation, prompt hijacking of the task flow, or unnecessary exposure of agent capabilities in the wrong context.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.