Back to skill

Security audit

Work Productivity Gog Google Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-style workflow helper with broad activation wording but no hidden code, credential access, persistence, or destructive behavior.

Before installing, be aware that this skill may be invoked by broad Google, Workspace, or CLI-related requests. If your platform allows it, consider disabling implicit invocation or using the explicit skill name for tasks that truly need this workflow helper.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrases are very broad and overlap with common productivity terms like 'google', 'workspace', 'cli', and generic requests for help, which can cause the skill to activate in contexts the user did not specifically intend. In an agent environment, ambiguous activation can route unrelated tasks into this skill, leading to incorrect actions, irrelevant guidance, or accidental handling of sensitive Google Workspace workflows without clear user consent.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrases are broad, natural-language sentences and generic keywords like 'google', 'workspace', and 'cli', which can cause the skill to activate for unrelated everyday requests. In an agent environment, overbroad invocation can route unintended tasks into this skill, increasing the chance of inappropriate actions, data exposure, or workflow confusion.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill description and use guidance are broad enough to match many common requests unrelated to a narrowly scoped Google workflow helper. This can cause unintended invocation, leading the agent to apply the wrong skill, expose irrelevant capabilities, or bypass more appropriate safeguards attached to better-scoped skills.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The keyword list contains highly generic terms such as 'google', 'workspace', and 'cli', which are ambiguous across many unrelated tasks. Over-broad triggers increase accidental activation frequency and can route user requests into an ill-fitting skill, creating reliability and security issues if the skill handles data or actions under the wrong context.

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger keywords are overly broad and include generic terms like 'google', 'workspace', 'cli', and common app names, which can cause the skill to activate for unrelated requests. In an agent environment, this increases the chance of misrouting user tasks, applying the wrong workflow, or surfacing irrelevant automation guidance when a narrower or safer skill should handle the request.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The skill description states broad usage conditions like 'when a user asks for work-productivity, gog, google, workspace, cli' without clearly defining boundaries or required context. This ambiguity can cause the orchestrator or user to invoke the skill in situations outside its intended scope, reducing reliability and potentially interfering with more appropriate skills.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The default prompt uses a very broad natural-language invocation phrase tied to generic productivity terms, which can cause the skill to be selected in contexts the user did not explicitly intend. This increases the chance of prompt-scope confusion, unintended tool routing, or accidental exposure of the skill's behavior during unrelated conversations.

Vague Triggers

Medium
Confidence
95% confidence
Finding
Enabling implicit invocation without a narrowly scoped activation policy allows the agent platform to auto-trigger this skill based on ambiguous user requests. In a broadly defined productivity domain, that can lead to unintended activation, misrouting, and increased attack surface if adversarial prompts are crafted to hijack or steer the skill indirectly.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger phrases are broad, natural-language sentences containing generic requests like 'Help me' and 'I need a practical workflow', which can cause the skill to activate for unrelated user prompts that merely mention common productivity terms. In an agent environment, unintended invocation can route tasks to the wrong skill, increasing the chance of inappropriate actions, confusing outputs, or accidental access to connected Google Workspace-related context.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.