Back to skill

Security audit

Work Productivity Agent Browser Workflow Helper

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only workflow helper with sloppy broad triggers, but it does not install code, request credentials, persist itself, or perform hidden actions.

Installers should know this skill may be invoked for broad browser, automation, or productivity prompts because its triggers are loose. Review or narrow the trigger metadata if you want precise activation, but no credential access, hidden install behavior, destructive action, or persistence was found.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Vague Triggers

High
Confidence
98% confidence
Finding
The trigger sentences are broad, awkwardly templated, and include generic phrases such as 'Help me' and 'I need a practical workflow', which can cause the skill to activate for routine user requests outside its intended scope. In an agent ecosystem, overbroad invocation can route unrelated tasks into this skill, leading to inappropriate automation guidance, reduced reliability, and accidental execution of workflows the user did not explicitly request.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The trigger phrases are broad, natural-language requests that can match ordinary user prompts without strong activation boundaries. This can cause unintended skill invocation, routing the conversation into browser or automation-oriented behavior when the user did not explicitly request this skill, increasing the risk of prompt hijacking, overreach, or unsafe automation in a high-capability context.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrases are broad, generic, and partially duplicated from the demand statement, which can cause the skill to activate outside its intended scope. In an automation/browser workflow context, overbroad activation increases the chance that users invoke the wrong skill for sensitive browsing, headless automation, or bug-fix tasks, leading to unsafe or unintended actions.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The description says the skill should be used when a user asks for very broad categories like work-productivity, browser, headless, automation, or practical workflow support. Because these categories are common across many tasks, the skill may be selected for unrelated prompts, expanding its operational scope beyond what users intended.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The trigger keywords are extremely broad, including generic terms like "browser," "automation," and "cli," which are likely to match many unrelated user requests. This can cause the skill to activate outside its intended scope, leading to inappropriate instruction injection, user confusion, or interference with more suitable skills.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill description defines usage conditions very broadly across generic topics like work productivity, browser, headless, and automation, without clear scoping constraints. This makes routing ambiguous and raises the risk of unintended activation, which can expose users to irrelevant or mismatched guidance and reduce trust in system behavior.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger list includes very broad everyday terms such as "browser", "automation", and "cli", which can cause the skill to activate in many unrelated conversations. Over-broad activation increases the chance that this skill intercepts requests outside its intended scope, leading to confusing behavior, unsafe workflow suggestions in the wrong context, or accidental delegation to a capability the user did not intend to invoke.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The default prompt trigger is extremely broad and includes generic productivity and browser-workflow language, which can overlap with normal user requests. This creates a prompt-routing risk where the skill may be invoked unintentionally, causing the agent to inject skill behavior or instructions into unrelated conversations without clear user intent.

Vague Triggers

Medium
Confidence
96% confidence
Finding
Enabling implicit invocation without strict activation constraints allows the platform to auto-select this skill based on vague similarity to user requests. Because this skill targets broad browser, automation, workflow, and productivity use cases, it can be pulled into many contexts unexpectedly, increasing the chance of unintended instruction injection, policy bypass through tool routing, or user confusion about why the skill was activated.

Natural-Language Policy Violations

Low
Confidence
80% confidence
Finding
The document mixes English with Chinese titles and content in the evidence section, but does not explain whether multilingual content is optional or intentionally locale-specific. Under the policy, forcing or assuming a language/locale without opt-in can be a natural-language policy concern.

Natural-Language Policy Violations

Low
Confidence
81% confidence
Finding
Most user-facing headings and explanatory text in this file are presented in Chinese, but the document does not indicate that language selection is optional or that the skill is region-specific. Under the stated policy, forcing a specific language without user opt-in can be a locale-policy concern.

Vague Triggers

Low
Confidence
88% confidence
Finding
The example trigger sentences are truncated and malformed, and they do not establish clear boundaries for when the skill should or should not activate. Poorly specified triggers increase the chance of accidental matching and make downstream routing behavior unpredictable.

Static analysis

No suspicious patterns detected.