Back to skill

Security audit

Work Productivity Agent Browser Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with broad activation wording, but it does not install code, request credentials, persist, or perform hidden actions.

Before installing, consider whether you want this helper to activate implicitly. Its content appears safe and purpose-aligned, but the trigger wording should ideally be narrowed so ordinary browser, CLI, or automation requests do not accidentally route into this skill.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger sentence is broad and phrased like normal user language, which increases the chance the skill activates in unintended contexts. In an automation/browser-workflow skill, accidental invocation can steer an agent into applying workflow instructions or browser-oriented behavior when the user did not explicitly request this skill, creating misexecution and prompt-routing risk.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases are extremely broad and include generic terms like 'browser', 'automation', and 'cli', which can cause the skill to activate outside its intended scope. In an agent environment, over-broad activation increases the chance of unintended invocation, prompt-routing mistakes, and execution of workflows against the wrong user request or context.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger list includes very broad terms like 'browser', 'automation', and 'cli', which are common across many unrelated requests. This can cause the skill to activate outside its intended scope, leading to prompt hijacking of routing, irrelevant execution, or accidental prioritization of this skill over more appropriate and safer specialized skills.

Vague Triggers

High
Confidence
95% confidence
Finding
The description says to use the skill whenever a user asks for broad categories like 'browser', 'headless', 'automation', or needs almost any workflow or analysis support. These ambiguous activation conditions substantially widen the matching surface, increasing the chance of unintended invocation and causing this skill to intercept requests that should be handled by narrower, context-appropriate skills.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger keywords are very broad, including generic terms like 'browser', 'automation', and 'cli', which commonly appear in unrelated requests. This can cause the skill to activate outside its intended scope, leading to incorrect routing, unexpected instruction injection into unrelated tasks, or accidental use of browser/headless workflows where they are unnecessary.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill description defines applicability in overly broad terms and mixes many adjacent concepts without clear boundaries. Because the activation criteria are vague, the system may select this skill for general productivity or browser-related requests, increasing the chance of irrelevant guidance, privilege overreach in workflow selection, and unsafe automation recommendations in contexts the skill was not designed for.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The default prompt uses a very broad activation phrase tied to generic terms like work-productivity, browser, automation, and practical help, which can cause the skill to be invoked in contexts far beyond its intended scope. Combined with allow_implicit_invocation: true, this increases the chance of unintended routing, prompt shadowing, or the skill being selected for loosely related user requests, potentially exposing users to unsafe or irrelevant workflow behavior.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger sentence is so broad and awkwardly templated that it can match ordinary user requests about help, workflows, browsers, or automation without a clear boundary. This creates unintended skill activation and prompt-scope capture, which can route unrelated conversations into this skill and cause unsafe or confusing behavior in downstream agent workflows.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger descriptions and examples do not define clear activation boundaries, so many general productivity or browser-related requests could be interpreted as matching this skill. In an agent ecosystem, ambiguous routing is dangerous because it can cause overbroad invocation, incorrect tool selection, and accidental execution of automation-oriented guidance in contexts where it was not intended.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.