Back to skill

Security audit

Work Productivity Gog Google Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overly broad Google/workflow triggers, but it does not install code, access credentials, persist, or perform actions on user data.

Install only if you want a generic planning/checklist helper for Gog-style Google Workspace workflows. Treat it as advisory, verify any workflow before applying it to real Gmail, Calendar, Drive, Contacts, or business data, and consider narrowing its triggers or disabling implicit invocation if accidental activation would be disruptive.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (13)

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The skill metadata and description advertise broad Google Workspace assistance, but the body only provides a generic workflow-writing template and no Gmail, Calendar, Drive, or Contacts-specific logic, safeguards, or operational constraints. This mismatch can cause unsafe reliance, improper invocation for sensitive productivity tasks, and overbroad delegation in contexts involving business data.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The trigger list includes Gmail, Calendar, Drive, and Contacts, but the skill does not define corresponding domain-specific handling. Overbroad triggers increase the chance the skill is auto-selected for sensitive Google Workspace requests where it may provide generic or incorrect guidance, leading to privacy, reliability, or workflow mistakes.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger sentences are broad, natural-language phrases that could match ordinary user requests without a clear opt-in or boundary for when this skill should activate. In an agent ecosystem, this can cause unintended invocation, leading the skill to handle requests outside its intended scope and increasing the chance of unsafe workflow execution or confusing task routing.

Vague Triggers

High
Confidence
90% confidence
Finding
The trigger examples are broad enough to match ordinary productivity requests and generic help-seeking language, which can cause the skill to activate outside its intended scope. In an agent ecosystem, overly broad activation increases the chance of inappropriate invocation, confusing users, and routing unrelated tasks into a workflow that may request unnecessary context or perform unintended actions.

Vague Triggers

High
Confidence
95% confidence
Finding
The skill description is broad enough to match many ordinary productivity requests, including generic terms like 'google', 'workspace', 'cli', and 'analysis'. In an agentic routing system, this can cause the skill to activate outside its intended scope, leading to prompt-surface expansion, misrouting, and increased exposure to unsafe or irrelevant instructions.

Vague Triggers

High
Confidence
97% confidence
Finding
The keyword list contains highly ambiguous triggers such as 'google', 'workspace', 'cli', 'gmail', 'calendar', and 'bug fix', which are common across many unrelated tasks. This makes accidental invocation likely and can let the skill intercept broadly scoped user requests, reducing routing integrity and potentially causing unsafe actions under the wrong workflow assumptions.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The example trigger sentences use vague phrases like 'help me' and 'I need a practical workflow' without establishing clear boundaries for when this skill should versus should not activate. These examples can train or encourage over-broad invocation behavior, compounding the ambiguous description and keyword issues already present in the skill.

Vague Triggers

High
Confidence
89% confidence
Finding
The activation keywords are overly broad and overlap with common conversation topics and generic task requests. In an agent environment, this can cause frequent accidental invocation and context capture during unrelated user interactions, which is more dangerous because the skill claims productivity and Google-related coverage that may involve sensitive enterprise data.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The activation condition in the description is vague and lacks clear boundaries for when the skill should or should not be used. This ambiguity increases the risk of inappropriate routing, especially in mixed productivity contexts where users may mention Google or CLI terms without intending this specific workflow helper.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill enables implicit invocation without defining narrow triggers or scope limits, which can cause the agent to activate this skill for loosely related requests. In practice, that increases the chance of prompt-routing abuse, unintended skill execution, and user confusion about which instructions are controlling the session.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The default prompt uses broad, everyday wording such as helping with workflows, bugs, hardening, and practical support, which overlaps with many common user requests. Combined with implicit invocation, this makes overbroad matching more likely and can route unrelated conversations into this skill, expanding the attack surface and causing unintended behavior.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentence begins with an everyday phrase ('Help me') tied to a long, generic requirement description, which is broad enough to match many unrelated user requests. In an agent-routing system, this can cause accidental invocation of the skill outside its intended scope, leading to misrouting, irrelevant automation, or unsafe overreach into Google/Workspace-style tasks.

Vague Triggers

Medium
Confidence
91% confidence
Finding
Although the sentence adds more words, it is still semantically ambiguous because it describes a meta requirement rather than a concrete user task. This increases the chance that normal requests about productivity or workflows are incorrectly interpreted as a match, which can degrade reliability and cause unintended skill execution.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.