Back to skill

Security audit

Work Productivity Gog Google Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a text-only workflow helper with no executable code, credentials, persistence, or data-moving behavior, though its auto-invocation triggers are broader than ideal.

Before installing, be aware that this skill may be suggested for broad Google, Workspace, CLI, or bug-fix requests where a more specific skill would fit better. It does not appear to run code, access accounts, read private data, or persist anything on its own.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger sentences are broad enough to activate on generic requests about workflows, bug fixing, or hardening, which can cause the skill to run outside its intended scope. In an agent ecosystem, ambiguous activation boundaries increase the chance of unintended invocation, context hijacking, or the skill influencing tasks the user did not explicitly request.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are broad enough to match common requests about work productivity, Google Workspace, or bug fixing, which can cause the skill to activate outside its intended scope. This increases the chance of unintended invocation, user confusion, and accidental routing of unrelated tasks into this workflow, especially because the listed keywords are generic and high-frequency.

Vague Triggers

High
Confidence
97% confidence
Finding
The skill description is broad enough to match many ordinary productivity, Google, CLI, or workflow requests, which can cause the skill to activate outside its intended niche. Over-broad activation increases the chance that unrelated user requests are silently steered by this skill's instructions, creating prompt-routing and policy-conflict risk across many sessions.

Vague Triggers

High
Confidence
98% confidence
Finding
The keyword triggers are highly generic, especially terms like 'google', 'workspace', 'cli', 'gmail', 'calendar', and 'bug fix', which are common across many unrelated tasks. This makes accidental invocation likely and allows the skill to intercept broad categories of user intent, reducing routing precision and potentially overriding more appropriate skills or safety logic.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The example triggers use everyday language like 'Help me' and 'I need a practical workflow' combined with broad problem statements, signaling that normal conversational requests should activate the skill. These examples encourage overmatching in downstream routing systems and make it more likely that the skill captures ambiguous requests not actually about this specialized requirement.

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger list includes broad, high-collision terms such as "google", "workspace", "cli", and "bug fix", which can cause the skill to activate in many unrelated contexts. Over-triggering can route users into the wrong workflow, producing irrelevant guidance or overshadowing safer, more specific skills, especially in agentic environments that auto-select tools based on keyword matches.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill description says it should be used whenever a user asks about broad categories like work-productivity, google, workspace, or cli, or needs almost any practical workflow, checklist, analysis, or implementation support for the requirement. This lacks clear boundaries and negative cases, increasing the chance of accidental invocation for unrelated requests and unsafe task routing.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The default prompt is extremely broad and self-invoking, using generic terms like work-productivity, workflow, and practical help without meaningful constraints. This can cause the skill to activate in unrelated contexts, increasing the chance of prompt-scope confusion, unintended handling of user requests, or inappropriate delegation to a skill the user did not explicitly intend to use.

Vague Triggers

Medium
Confidence
93% confidence
Finding
Enabling implicit invocation without a tightly scoped trigger policy allows the skill to be auto-selected based on vague similarity to many common workplace requests. In a productivity-oriented skill with broad domain language, this raises the risk of accidental invocation, overreach into unrelated tasks, and unexpected exposure of user context to the skill.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentence is so broad and natural-language-like that it can cause the skill to activate for ordinary user requests that merely resemble the topic. That increases the chance of unintended invocation, context bleed, and the skill being applied where its assumptions or automation patterns are not appropriate.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The invocation guidance uses broad keywords and generic prompt stems without strong scope boundaries, making accidental or overbroad routing likely. In an agent setting, ambiguous routing can expose user data or tasks to an irrelevant skill, produce incorrect outputs, or let this skill preempt more appropriate tooling.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.