Back to skill

Security audit

Work Productivity Gog Google Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-style workflow helper with overly broad activation wording but no evidence of hidden execution, credential access, persistence, or data exfiltration.

Before installing, be aware this skill may be invoked for broad Google, Workspace, CLI, or productivity requests. It appears safe as a guidance-only skill, but users who want precise routing should narrow or disable implicit invocation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger sentences are broad enough that the skill may activate for loosely related requests involving productivity, Google, or workflows, increasing the chance of unintended invocation. In an agent setting, ambiguous activation can route user tasks into the wrong skill, causing inappropriate actions, misleading guidance, or unnecessary access to Google Workspace-related contexts.

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger phrases are broad enough to match ordinary productivity requests and generic help prompts, which can cause the skill to activate outside its intended scope. In an agent ecosystem, this increases the chance of inappropriate routing, unexpected capability use, or user confusion about what workflow is being invoked.

Vague Triggers

High
Confidence
95% confidence
Finding
The skill description is written so broadly that it can match many ordinary productivity or implementation-help requests unrelated to this specific workflow. In agent routing systems, overly broad matching can cause unintended invocation, leading the skill to intercept prompts outside its intended scope and potentially override more appropriate, safer, or more specialized skills.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger list includes very common terms such as 'google', 'workspace', 'cli', and 'bug fix', which are likely to appear in many unrelated requests. This makes accidental activation significantly more likely, creating routing collisions and broadening the skill's operational scope beyond what users intended.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example triggers are vague and affirmative-only, with no clear boundaries for non-matching cases. Without explicit negative cases or scope limits, downstream systems or maintainers may treat the skill as applicable to a wide range of similar prompts, increasing confusion and misrouting risk.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger keyword list is overly broad and includes common terms like 'google', 'workspace', and 'cli', which can cause the skill to activate in many unrelated conversations. In an agent system, accidental invocation can misroute tasks, expose irrelevant capabilities, and increase the chance that the model follows the wrong workflow for sensitive user requests.

Vague Triggers

High
Confidence
91% confidence
Finding
The skill description defines usage in vague, expansive terms such as when a user asks about work-productivity, gog, google, workspace, or needs a practical workflow or analysis, without meaningful exclusion criteria. This ambiguity increases the likelihood of inappropriate selection for unrelated or partially related tasks, which can cause unsafe delegation, incorrect guidance, or policy bypass through accidental tool routing.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The default prompt is written as a broad, natural-language trigger tied to common productivity terms and general user needs, which can cause the skill to activate in many ordinary conversations without clear user intent. In a workflow/helper skill that may influence setup, analysis, or implementation guidance, overbroad activation increases the chance of unintended invocation, context hijacking, or the skill steering responses when the user did not explicitly request it.

Vague Triggers

Medium
Confidence
95% confidence
Finding
Enabling implicit invocation without scoped conditions allows the platform to call this skill automatically based on loose relevance matching rather than deliberate user selection. Combined with the broad work-productivity context, this makes accidental or excessive invocation more likely, which can expose users to unintended behavioral influence, prompt-scope expansion, or misapplication of the skill in unrelated conversations.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger sentence is phrased so broadly that it can match ordinary user language rather than a narrow, intentional invocation of this skill. That creates misrouting risk: the agent may activate this workflow in unrelated contexts and produce actions or guidance the user did not intend, which is especially problematic for a productivity skill touching Google Workspace-style tasks.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger scope is ambiguous and lacks clear boundaries, so the routing layer has no reliable way to distinguish this skill from many generic work-productivity requests. In practice, this can cause accidental selection over safer or more appropriate skills, increasing the chance of irrelevant guidance, unintended workflow execution, or privilege misuse in adjacent integrations.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.