Back to skill

Security audit

Work Productivity Gog Google Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overbroad activation wording but no executable code, persistence, credential handling, or hidden high-impact behavior.

Before installing, be aware that this skill may trigger on broad Google, CLI, or productivity requests. It appears safe as a planning/checklist helper, but users should invoke it explicitly when they want this workflow assistance and avoid relying on it for account-changing Google Workspace actions without separate review.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are generic enough to match ordinary productivity or troubleshooting requests, which can cause the skill to activate outside its intended scope. In an agent ecosystem, over-broad routing increases the chance of unintended instruction injection, privacy exposure, or workflow execution in contexts the user did not explicitly choose.

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger phrases are broad enough to match ordinary productivity, Google Workspace, and bug-fix requests that are not specifically asking for this skill. In an agent-routing context, this can cause over-triggering, unexpected invocation, and accidental exposure of the skill's workflow or actions in unrelated conversations.

Vague Triggers

High
Confidence
96% confidence
Finding
The skill description and usage scope are so broad that they can match many ordinary productivity or Google-related requests, causing unintended activation. Overbroad routing increases the chance that this skill handles requests outside its intended safety boundary, which can lead to incorrect automation guidance, privilege misuse, or interference with more appropriate specialized skills.

Vague Triggers

High
Confidence
98% confidence
Finding
The keyword triggers are highly generic terms such as 'google', 'workspace', 'cli', and 'bug fix', which are common across many unrelated tasks. This makes accidental invocation likely and can divert sensitive or high-impact requests into a skill not explicitly designed or reviewed for them, expanding attack surface through skill misrouting and unsafe automation suggestions.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The example trigger sentences are malformed and repeat marketing text rather than providing clear, bounded activation examples. Poor examples weaken the safety boundary for routing, making it harder for maintainers and automated systems to distinguish legitimate invocation from incidental mention, which can result in unintended skill selection and confusing or unsafe outputs.

Vague Triggers

High
Confidence
91% confidence
Finding
The trigger list includes broad, high-collision terms such as "google", "workspace", and "cli", which are likely to appear in many unrelated user requests. This can cause the skill to activate outside its intended scope, increasing the chance of irrelevant instruction injection into conversations and unintended workflow execution guidance.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The usage condition in the description is overly broad and ambiguous, saying to use the skill whenever users mention general terms like work-productivity, google, workspace, or need practical support. Ambiguous activation boundaries make it easier for the skill to be selected in contexts it was not designed for, which can misroute requests and expose users to incorrect or overbroad operational guidance.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The example trigger phrases are written as generalized natural-language requests that resemble ordinary user conversation rather than distinct invocation patterns. This raises the likelihood of accidental activation through routine phrasing, especially when combined with the already broad keyword set.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The default prompt uses broad, everyday terms like work-productivity, google, workspace, cli, workflow, checklist, and analysis, which can cause the skill to activate in many unrelated conversations. This increases the chance of unintended invocation, context capture, and over-application of the skill beyond the user's actual intent.

Vague Triggers

Medium
Confidence
94% confidence
Finding
Enabling implicit invocation without tightly scoped routing criteria allows the system to auto-select this skill based on vague overlap with common productivity language. In this skill's context, the broad business-productivity domain makes accidental invocation more likely, which can lead to inappropriate tool behavior, prompt hijacking of normal tasks, or unnecessary exposure of user context to the skill.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentences are broad, natural-language phrases that overlap with ordinary user requests, which can cause the skill to activate unintentionally. In an agent ecosystem, overbroad invocation increases the chance that this skill is selected in the wrong context, leading to misrouting, unintended data exposure to the skill, or execution of workflows the user did not explicitly request.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.