Back to skill

Security audit

Work Productivity Gog Google Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overly broad trigger wording, but it does not request hidden access, credentials, persistence, or destructive actions.

Before installing, consider narrowing or manually invoking this skill so ordinary Google, CLI, Gmail, Calendar, Drive, or bug-fix requests are not routed to it by mistake. No special credentials or persistent access are requested by the artifact.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

High
Confidence
92% confidence
Finding
The trigger sentence is broad and phrased like a natural user request, which increases the chance that the skill will be invoked unintentionally during normal conversation. Unintended invocation can cause the wrong workflow to run, leading to confusing behavior, mis-scoped actions, or accidental handling of productivity data in a context the user did not explicitly intend.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The invocation guidance is ambiguous because it mixes broad keywords like 'google', 'workspace', and 'bug fix' with loosely defined trigger examples, making the skill's activation boundary unclear. In an agent ecosystem, unclear trigger scope can cause over-selection of this skill for unrelated requests, which may interfere with intended tool routing and increase the chance of unnecessary access to adjacent work-productivity workflows.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger phrases are broad and map to common words like 'google', 'workspace', 'cli', and generic requests for 'practical workflow', which can cause the skill to activate for many unrelated conversations. Over-broad activation increases the chance of unintended invocation, causing the agent to apply this skill in contexts the user did not intend, which can lead to incorrect actions, prompt hijacking of routing, or unsafe workflow execution if the skill later handles sensitive productivity tools.

Vague Triggers

High
Confidence
95% confidence
Finding
The skill description is broad and includes common workflow terms, which can cause the skill to activate for loosely related requests rather than clearly scoped Gog/Google Workspace workflow tasks. This increases the chance of unintended invocation, routing user requests into the wrong skill, and producing irrelevant or unsafe automation guidance in contexts the author did not intend.

Vague Triggers

High
Confidence
97% confidence
Finding
The keyword list contains ambiguous everyday terms such as 'google', 'workspace', 'cli', and 'bug fix', which are common across many unrelated requests. In a trigger-based system, this can cause frequent accidental invocation, misrouting, and overbroad access to contexts where the skill may offer actions or guidance outside its intended scope.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example triggers use very generic language like 'help me' and 'I need a practical workflow' while embedding broad requirement text, without clarifying what requests should not activate the skill. This weakens activation boundaries and reinforces overmatching behavior, making the skill easier to invoke unintentionally in ordinary productivity or troubleshooting conversations.

Vague Triggers

Medium
Confidence
92% confidence
Finding
触发关键词包含非常宽泛的词,如“google”“workspace”“cli”“bug fix”,且没有附加场景约束,容易在与该技能无关的普通请求中被错误触发。错误路由会让代理使用不匹配的工作流、给出偏题建议,甚至在涉及 Google Workspace 或命令行操作时造成不必要的权限引导或误操作风险。

Vague Triggers

Medium
Confidence
90% confidence
Finding
技能描述中的启用条件使用了较宽泛的任务表述,如“practical workflow, artifact, checklist, analysis, or implementation support”,但未限定必须与特定 Gog-style Google workflow 需求直接相关。这会扩大技能适用面,增加在不相干任务上被激活的概率,导致错误委派、结果失焦,或把用户带入不必要的自动化/实现步骤。

Vague Triggers

Medium
Confidence
95% confidence
Finding
The default prompt is broadly phrased and can activate on generic terms like work-productivity, workflow help, bugs, hardening, or practical support without tight scope boundaries. Combined with implicit invocation, this increases the chance the skill is triggered in contexts the user did not clearly intend, which can cause inappropriate tool behavior, prompt injection exposure, or unintended handling of unrelated tasks.

Vague Triggers

High
Confidence
98% confidence
Finding
The trigger sentences are written as broad, ordinary-language prompts that can match many unrelated user requests, causing the skill to activate outside its intended scope. In an agent environment, overbroad activation can lead to prompt hijacking of routing, unintended access to tools or workflows, and user confusion about why this skill was selected.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.