Back to skill

Security audit

Work Productivity Gog Google Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overly broad activation wording, but it does not install code, request credentials, run commands, or access Google data itself.

Before installing, understand that this skill may be selected too often for ordinary Google, Gmail, Calendar, Drive, CLI, or bug-fix requests. It appears safe as a guidance-only helper, but users or maintainers should narrow the activation keywords and implicit prompt so unrelated work content is less likely to be routed through it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger sentences are very broad, repetitive, and loosely scoped, which can cause the skill to activate for vague or only partially related requests. In an agent ecosystem, ambiguous activation can route user tasks into the wrong workflow, increasing the chance of unintended actions, incorrect outputs, or misuse of connected productivity tooling.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The documented trigger phrases are very broad and include generic terms like work-productivity, google, workspace, cli, gmail, calendar, and bug fix, which can cause the skill to activate for many ordinary user requests unrelated to the intended scoped workflow. Over-broad invocation increases the chance of accidental routing, privilege overreach, or the skill handling requests outside its tested safety assumptions.

Vague Triggers

High
Confidence
94% confidence
Finding
The skill description is broad enough to match many ordinary productivity or Google-related requests, which can cause the skill to activate outside its intended scope. Over-broad routing increases the chance that users are funneled into irrelevant or lower-safety workflows, and in agent systems this can become a prompt-selection weakness that affects downstream behavior.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger keywords include very generic terms such as "google," "workspace," "cli," "gmail," "calendar," and "drive" without negative boundaries or disambiguation rules. In a skill-routing environment, these terms are likely to collide with many unrelated user requests, causing accidental invocation and potentially overriding more appropriate or safer specialized skills.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger list includes very common terms such as "google", "workspace", "cli", "gmail", and "calendar", which are likely to match many unrelated user requests. This can cause the skill to activate outside its intended scope, leading to incorrect routing, user confusion, or unintended handling of requests that may involve sensitive productivity data.

Vague Triggers

High
Confidence
90% confidence
Finding
The description says to use the skill whenever a user mentions broad categories like work-productivity, gog, google, workspace, or cli, or whenever they need practical workflow or implementation help for the requirement. This is ambiguous and expansive, making it difficult to determine when the skill should or should not run, increasing the chance of accidental invocation and overlap with other skills.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The default prompt contains broad activation language tied to common productivity terms and generic user needs, which can cause the skill to be selected in ordinary conversations where the user did not explicitly request it. This creates an invocation-scope problem: the skill may receive context and influence outputs unexpectedly, increasing the risk of prompt injection exposure, unintended actions, or incorrect delegation.

Vague Triggers

Medium
Confidence
95% confidence
Finding
Enabling implicit invocation without tightly scoped activation constraints allows the platform to auto-select this skill based on vague similarity rather than deliberate user choice. In a productivity and Google Workspace context, that increases the chance the skill is invoked around sensitive work content, expanding access to prompts and artifacts beyond what the user intended.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger sentence is broad enough to match ordinary user phrasing about getting help or needing a workflow, which can cause the skill to activate outside its intended scope. Over-broad activation increases the chance that this skill intercepts unrelated requests and influences agent behavior in contexts the user did not intend, especially because the skill is framed around generic productivity and workflow support.

Vague Triggers

Medium
Confidence
90% confidence
Finding
This trigger is ambiguously scoped because it describes a very general need for a practical workflow without clear constraints, making it hard to tell when the skill should or should not engage. Ambiguous activation boundaries can lead to accidental invocation, prompt-routing errors, and unintended access to user tasks that belong to other skills or default handling paths.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.