Back to skill

Security audit

Work Productivity Gog Google Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with broad activation wording, but it does not request credentials, execute code, access Google data, or persist in the environment.

Before installing, understand that this skill may activate on broad Google or productivity wording. Use it as planning/checklist guidance, and require explicit confirmation before letting any agent read or change Gmail, Calendar, Drive, Contacts, or other sensitive workspace data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger examples are broad, generic, and closely resemble ordinary user requests, which can cause the skill to activate outside its intended scope. In a productivity skill tied to Google/Workspace workflows, overbroad activation increases the chance of the agent handling sensitive email, calendar, drive, or contacts tasks without sufficiently clear user intent or safety gating.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The README references Google Workspace-related domains such as Gmail, Calendar, Drive, and Contacts but provides no warning that these may involve access to sensitive personal or organizational data. Without privacy and permission guidance, users may invoke the skill in contexts involving confidential content, creating elevated risk of unintended data exposure, oversharing, or unsafe automation.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are broad and generic enough to match common user requests about productivity, workflows, bug fixes, or practical help, which can cause the skill to activate outside its intended scope. In an agent ecosystem, overbroad activation increases the chance of unintended invocation, confused task routing, and unnecessary exposure of the skill’s instructions or behaviors in contexts the user did not ask for.

Vague Triggers

High
Confidence
95% confidence
Finding
The skill description contains broad terms like 'work-productivity', 'google', 'workspace', 'cli', and generic offers of 'practical workflow, artifact, checklist, analysis, or implementation support,' which can cause the skill to be invoked for many unrelated user requests. Over-broad routing increases the chance of inappropriate activation, causing instruction interference, user confusion, and possible unsafe application of this skill outside its intended scope.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger keyword list includes highly generic words such as 'google', 'workspace', 'cli', and 'bug fix' that have substantial overlap with everyday requests. This makes accidental or excessive invocation likely, which is dangerous because the skill may override more appropriate specialized handling and route unrelated tasks into a broad workflow assistant context.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The example trigger phrases are written as natural everyday requests with little disambiguation, so they can match ordinary conversations rather than explicit skill-invocation scenarios. This broadens the activation surface and reinforces ambiguous routing behavior, increasing the risk of unintended skill selection and reduced reliability of agent behavior.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger list is overly broad, including generic terms like "google", "workspace", "cli", and common app names such as "gmail", "calendar", and "drive". This can cause the skill to activate for many unrelated requests, leading to unintended routing, irrelevant automation, and possible exposure of user context to a skill that was not the best match.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The invocation description is broad and activates on general needs like practical workflows, checklists, analysis, or implementation support across common productivity topics. Because the boundaries are unclear, the skill may be selected for requests outside its intended scope, increasing the chance of incorrect tool use, confused delegation, or unnecessary handling of sensitive productivity-related context.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill enables implicit invocation without any visible trigger constraints, which can cause the agent to auto-select this skill in situations broader than intended. Because the skill is framed as general workflow/help functionality, ambiguous activation increases the chance of unintended use, prompt-scope expansion, or inappropriate handling of user requests that were not meant for this skill.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger sentence is so broad and natural-language-like that it can match ordinary user requests unrelated to this specific skill, causing over-activation. In an agent ecosystem, that increases the chance the skill is invoked in the wrong context, which can lead to inappropriate access to Google/Workspace-related workflows, confused task routing, or unintended action suggestions.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The activation guidance lacks clear boundaries about when the skill should and should not be used, so the orchestrator or user may route many loosely related requests into this skill. Because the skill covers broad productivity and Google workflow areas, ambiguous triggering increases the risk of unintended invocation, poor least-privilege behavior, and unsafe handling of tasks beyond the skill's intended scope.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.