Back to skill

Security audit

Work Productivity Gog Google Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-style workflow helper with broad activation wording, but it does not include executable code, credential access, persistence, or hidden data flows.

Before installing, be aware that this skill may activate too often for general Google, CLI, or productivity requests. It appears low risk as a guidance-only skill, but narrowing its triggers would make routing more predictable.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger sentences are broad enough to activate on generic productivity, Google Workspace, CLI, or bug-fix requests that may not actually require this skill. In an agent-routing context, overly permissive triggers can cause unintended invocation, increasing the chance that the agent applies inappropriate instructions or accesses related workflows in situations outside the user's intent.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger phrases are broad enough to match ordinary requests about productivity, Google Workspace, CLI, or bug fixing, which can cause the skill to activate outside its intended scope. In an agent ecosystem, overbroad routing can expose users to unintended instructions or workflow behavior and increases the chance of prompt-space hijacking through accidental invocation.

Vague Triggers

High
Confidence
96% confidence
Finding
The skill description is broad enough to match common terms like 'google', 'workspace', 'cli', and generic requests for workflows, artifacts, or analysis. That can cause unintended invocation in unrelated contexts, leading the agent to apply this skill when it lacks clear relevance and potentially exposing users to inappropriate guidance or overshadowing better-scoped skills.

Vague Triggers

High
Confidence
98% confidence
Finding
The trigger keywords are highly generic and include broadly used terms like 'google', 'workspace', 'cli', 'gmail', 'calendar', and 'bug fix' without contextual constraints. In a routing system, this can cause frequent accidental activation across many unrelated tasks, increasing the chance of misrouting, response contamination, or bypass of more appropriate specialized skills.

Vague Triggers

High
Confidence
93% confidence
Finding
触发关键词包含非常常见且高频的词,如“google”“workspace”“cli”“bug fix”等,容易与大量普通用户请求重叠,导致该技能在非预期场景被误触发。误触发会让代理把与 Google/工作流无关的请求路由到此技能,造成错误执行、上下文污染或绕过更合适技能的安全边界。

Vague Triggers

Medium
Confidence
86% confidence
Finding
技能描述将适用范围表述为一组宽泛主题和“需要实用流程、产物、检查清单、分析或实现支持”之类的开放式条件,没有清晰说明边界或排除条件。这会让技能选择逻辑难以精确判断,增加被不相关请求激活的概率,进而影响路由正确性和结果可靠性。

Vague Triggers

Medium
Confidence
91% confidence
Finding
The default prompt is overly broad and uses generic phrases like 'help me' and broad productivity language that can match many ordinary user requests. This can cause accidental invocation or prompt-scope bleed, where the skill is engaged outside its intended context and influences conversations unexpectedly.

Vague Triggers

Medium
Confidence
97% confidence
Finding
Implicit invocation is enabled even though the manifest does not define clear trigger constraints or a tightly scoped purpose. In combination with the broad prompt and unclear description, this increases the chance of unintentional activation and inappropriate routing of user requests to this skill.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger sentences are written as broad natural-language requests that resemble ordinary user prompts rather than narrowly scoped invocation examples. This can cause unintended activation of the skill in unrelated conversations, leading the agent to apply the wrong workflow, expose irrelevant capabilities, or override more appropriate task routing.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The keyword list includes very broad terms such as 'google', 'workspace', 'cli', and 'bug fix', which are common across many unrelated tasks. Overbroad trigger keywords increase the chance of accidental skill selection, causing misrouting, unexpected behavior, and potentially unsafe delegation if the skill is invoked outside its intended scope.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.