Back to skill

Security audit

Work Productivity Gog Google Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with broad activation wording, but it does not install code, request credentials, persist, or perform actions on its own.

Before installing, be aware that this skill may be invoked for broad Google, CLI, or productivity requests where a more specific skill would be better. It is otherwise a low-risk advisory helper; review outputs before using any generated workflow or script against real Google Workspace data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Vague Triggers

High
Confidence
87% confidence
Finding
The documented trigger phrases are broad and generic, including common terms like work-productivity, google, workspace, cli, gmail, calendar, and bug fix. This increases the chance the skill will be invoked in contexts the user did not intend, which can route tasks to the wrong workflow, cause confused-deputy behavior, or expose connected Google Workspace operations unnecessarily if the skill is granted sensitive capabilities.

Vague Triggers

High
Confidence
96% confidence
Finding
The skill description is broad enough to activate on very common requests involving generic terms like work-productivity, google, workspace, or cli, which can cause the agent to invoke this skill outside its intended scope. Over-broad activation increases the chance of prompt/skill hijacking at routing time, where this skill preempts more appropriate or safer skills and influences responses for unrelated user tasks.

Vague Triggers

High
Confidence
98% confidence
Finding
The keyword list includes highly ambiguous generic triggers such as google, workspace, cli, gmail, calendar, drive, contacts, and bug fix, all of which are common across many unrelated tasks. In a skill-routing system, such unspecific triggers can cause accidental activation and let this skill intercept broad categories of user requests, reducing routing integrity and potentially exposing users to irrelevant or unsafe guidance.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example trigger sentences demonstrate activation using vague, reusable phrasing and do not communicate where the skill should not apply. This makes the routing boundary unclear to maintainers and increases the likelihood that matching logic or future authors copy these examples into overly permissive trigger patterns.

Vague Triggers

Medium
Confidence
88% confidence
Finding
触发关键词包含非常通用的词,如“google”“workspace”“cli”“bug fix”,且未配合明确的上下文约束,容易在大量无关请求中误触发该技能。误触发会导致代理选择错误的工作流、生成不相关操作建议,进而带来越权执行、误操作外部工具或混淆用户意图的安全与可靠性风险。

Vague Triggers

Medium
Confidence
84% confidence
Finding
技能描述将适用场景表述为用户提到多个宽泛主题或需要“实用流程、产物、检查清单、分析或实现支持”时即可使用,激活边界非常模糊。这样的描述会扩大技能匹配面,使代理在并不适合的上下文中调用该技能,增加错误建议、错误自动化以及对敏感工作流进行不必要介入的概率。

Vague Triggers

Medium
Confidence
92% confidence
Finding
The default prompt trigger is broad and tied to common productivity and workflow language, which increases the chance of unintended or implicit invocation during ordinary user requests. Because implicit invocation is enabled, the skill may activate when users did not explicitly request it, causing prompt-scope expansion and unexpected influence over downstream behavior.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger phrases are broad, natural-language requests that can match ordinary user prompts unrelated to this specific skill, causing over-activation or accidental routing. In an agent ecosystem, this can lead to the wrong skill taking control of tasks, creating confusing behavior, data overexposure to an unnecessary workflow, or unsafe automation being invoked without clear user intent.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.