Back to skill

Security audit

Work Productivity Gog Google Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with broad triggers, but it does not install code, request credentials, persist, or perform hidden actions.

Install this only if you want a broad workflow-planning helper for Gog-style Google Workspace productivity tasks. Be aware that its implicit triggers are loose; prefer explicit invocation by skill name when you want it, and review outputs before applying any suggested code or workflow changes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger sentences are generic enough to match ordinary user requests about productivity, workflows, bug fixing, or setup hardening, which can cause the skill to activate outside its intended scope. Over-broad invocation increases the chance of unintended tool use, user confusion, or routing sensitive requests into a skill that may perform actions or provide guidance without sufficiently specific user intent.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger phrases are extremely broad and map to common productivity requests, increasing the chance this skill is invoked unintentionally for unrelated user intents. In an agent environment, overbroad activation can cause the wrong workflow to take control, leading to inappropriate actions, confusing outputs, or unsafe handling of Google Workspace-related tasks without clear user consent.

Vague Triggers

High
Confidence
96% confidence
Finding
The skill description is extremely broad and matches common terms like work-productivity, google, workspace, and cli without meaningful scoping. This can cause the skill to activate for many unrelated requests, letting its instructions inappropriately steer agent behavior and increasing the chance of prompt-scope hijacking or unintended delegation.

Vague Triggers

High
Confidence
98% confidence
Finding
The trigger keywords include very generic terms such as google, workspace, cli, gmail, calendar, and bug fix, which are likely to appear in ordinary user requests far outside this skill's intended scope. Overbroad keyword activation can cause accidental invocation and instruction interference, especially in agent systems that route tasks automatically based on keyword matching.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example trigger phrases demonstrate activation on vague, everyday requests and reinforce an expansive interpretation of when the skill should be used. This increases the likelihood that downstream routers or authors will treat ordinary help requests as in-scope, broadening attack surface and causing the skill to override more appropriate specialized behavior.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger list is overly broad and includes generic terms like "google", "workspace", and "cli", which can cause the skill to be invoked in many unrelated contexts. This increases the chance of misrouting user requests, producing irrelevant automation guidance, or overshadowing more appropriate skills, especially in systems that auto-select skills based on keyword matching.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The description says the skill should be used whenever users ask about broad domains such as work productivity, Google, workspace, or CLI, without clearly bounding the intended job-to-be-done. In an agent environment, this can lead to accidental activation on loosely related requests and reduce reliability of task routing, which is a security and safety concern when skills influence downstream actions or recommendations.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The default prompt uses a very broad invocation phrase tied to common productivity and workflow language, which can cause the skill to trigger for ordinary requests unrelated to the user's explicit intent. In an agent ecosystem, this increases the risk of prompt-scope confusion, unintended skill routing, and untrusted instructions being injected into otherwise normal user interactions.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger examples are phrased so broadly that ordinary user requests about help, workflows, or setup could unintentionally match and invoke this skill outside its intended scope. In an agent ecosystem, over-broad invocation can cause the wrong skill to activate, leading to misrouting, unexpected access to connected Google Workspace-style workflows, or unreliable automation behavior.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.