Back to skill

Security audit

Work Productivity Gog Google Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a simple workflow helper with no executable code or credential access, but its broad automatic trigger wording could make it activate for loosely related Google or productivity requests.

This skill is reasonable to install if you want a generic workflow/checklist helper, but its trigger terms are loose. Consider invoking it explicitly or narrowing the trigger metadata before broad deployment so it does not handle unrelated Google, Gmail, Calendar, CLI, or bug-fix requests unexpectedly.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger sentences and keywords are broad enough that the skill may activate for loosely related requests involving general work productivity, Google Workspace, CLI, or bug fixing. In an agent ecosystem, ambiguous activation can cause the wrong skill to run, leading to unintended actions, irrelevant guidance, or unsafe workflow overlap with more privileged skills.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrases are generic enough to match ordinary productivity or Google Workspace requests, which can cause the skill to activate outside its intended scope. In an agent environment, this increases the chance of prompt routing collisions, unexpected behavior, or the skill handling requests without sufficiently specific user intent.

Vague Triggers

High
Confidence
97% confidence
Finding
The skill description is broad enough to match many ordinary productivity or Google-related requests, which can cause the skill to auto-activate outside its intended niche. Overbroad routing increases the chance of prompt-surface expansion, accidental tool use, or interception of tasks better handled by narrower, safer skills.

Vague Triggers

High
Confidence
98% confidence
Finding
The keyword list includes ambiguous everyday terms such as 'google', 'workspace', 'cli', 'gmail', 'calendar', and 'bug fix', all of which are common across many unrelated requests. This makes accidental triggering likely and can let the skill inappropriately capture user intent, creating unsafe scope creep and reduced predictability in multi-skill environments.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The example trigger sentences encourage activation from vague paraphrases rather than defining a strict boundary for when the skill should run. In practice, this trains routing systems or maintainers to treat broad problem statements as sufficient, increasing unintended activation and confusion about the skill's authority.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger keywords are overly broad and include common terms such as "google", "workspace", and "cli", which can cause the skill to activate for many unrelated requests. This increases the chance of incorrect routing, prompt-context pollution, and accidental invocation of workflow behavior in contexts where the user did not intend it.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The description says to use the skill when users ask about several broad categories or need general workflow/help artifacts, but it does not clearly separate in-scope from out-of-scope requests. Ambiguous activation conditions can make an orchestrator select this skill too often, reducing reliability and potentially applying the wrong instructions to unrelated user tasks.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The default prompt includes a long, generic trigger phrase tied to common productivity and workflow language, which increases the chance of unintended invocation in ordinary user requests. Because implicit invocation is enabled, this broad matching can cause the skill to activate when the user did not explicitly request it, expanding the attack surface and potentially injecting unrequested behavior into unrelated tasks.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentences and keyword set are broad enough to match ordinary user requests about general work productivity, Google Workspace, CLI, Gmail, Calendar, or bug fixing, which can cause the skill to activate when the user did not specifically intend it. Unintended invocation can route tasks into the wrong workflow, causing confused behavior, reduced reliability, and possible exposure of user context or actions to an overly permissive skill path.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.