Back to skill

Security audit

Work Productivity Gog Google Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a text-only workflow helper with no executable code, credential handling, persistence, or destructive behavior, though its activation wording is overly broad.

Install only if you want a general workflow/checklist helper for Gog or Google Workspace-related productivity tasks. Be aware that its broad implicit triggers may cause it to be selected for ordinary Google, CLI, or bug-fix requests; explicit invocation by skill name is safer.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger sentences are broad natural-language phrases that resemble ordinary user requests, which increases the chance the skill will be invoked unintentionally when a user is merely discussing workflow help or bug fixing. In an agent ecosystem, accidental invocation can misroute tasks, cause the wrong skill to act on user data or workspace resources, and reduce the user's ability to make informed execution choices.

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger phrases are generic and overlap heavily with normal user requests about productivity, Google Workspace, or workflow help. This can cause the skill to activate unexpectedly, increasing the chance that it intercepts unrelated conversations and influences agent behavior outside its intended scope.

Vague Triggers

High
Confidence
94% confidence
Finding
The manifest description includes very broad terms like 'work-productivity,' 'google,' 'workspace,' 'cli,' and generic requests for 'workflow, artifact, checklist, analysis, or implementation support.' This can cause the skill to activate for many ordinary user requests outside its intended niche, increasing the chance of unintended routing, prompt-surface expansion, and misuse of the skill in contexts it was not designed to handle.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger keywords include generic high-frequency terms such as 'google,' 'workspace,' 'cli,' 'gmail,' 'calendar,' 'drive,' and 'bug fix' without qualifiers. These broad triggers materially increase accidental invocation across unrelated requests, which can hijack task routing and apply this skill in contexts where its guidance may be irrelevant or unsafe.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example trigger sentences are vague and resemble common everyday requests, making them easy matches for unrelated user prompts. This reinforces over-broad activation behavior and may train selectors or maintainers toward permissive matching, increasing accidental use of the skill beyond its intended scope.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger keywords are overly broad and include common terms like 'google', 'workspace', and 'cli', which can match many unrelated user requests. This raises the chance of accidental skill invocation, causing the agent to apply this workflow in the wrong context and potentially override more appropriate skills or produce irrelevant actions.

Vague Triggers

High
Confidence
92% confidence
Finding
The skill description defines applicability in very broad terms, covering generic requests for workflows, checklists, analysis, or implementation support around common productivity topics. Because the activation boundary is unclear, the skill may be selected for many loosely related tasks, increasing misrouting risk and making unintended behavior more likely in multi-skill environments.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill enables implicit invocation while providing only broad, generic activation text tied to common productivity terms like work-productivity, google, workspace, cli, and workflow. This makes the skill eligible to trigger in many unrelated contexts, increasing the chance that its prompt and behavior are applied without clear user intent or adequate scoping, which can lead to unsafe or unexpected actions.

Vague Triggers

High
Confidence
91% confidence
Finding
The trigger phrases are so broad that ordinary user requests containing common terms like 'help me' or generic workflow language could invoke this skill outside its intended scope. Over-broad activation increases the chance of unintended execution, context confusion, and inappropriate handling of unrelated tasks, which is a real security and reliability issue for agent skills.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.