Back to skill

Security audit

Work Productivity Gog Google Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-style workflow helper with broad activation wording but no artifact evidence of hidden execution, data access, credential use, persistence, or destructive behavior.

Install only if you want a general workflow helper for Gog/Google Workspace-style productivity tasks. Because its trigger wording is broad and implicit invocation is enabled, users should be aware it may be selected for loosely related productivity or Google/CLI requests unless the platform lets them restrict activation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger sentences are written in broad, natural language that can match ordinary user requests rather than a clearly intentional invocation. In an agent ecosystem, this increases the chance the skill is activated unexpectedly, which can steer workflows, override user intent, or cause the agent to perform actions under the wrong skill context.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases are broad enough to match ordinary user requests like asking for general workflow help, bug fixing, or setup hardening, which can cause the skill to activate outside its intended scope. In an agent ecosystem, over-broad routing can unintentionally expose users to the skill's instructions or behaviors when they did not explicitly request this specific capability.

Vague Triggers

High
Confidence
95% confidence
Finding
The skill description and usage guidance are broad enough to match many ordinary productivity or Google-related requests, which can cause the skill to activate outside its intended scope. Over-broad activation increases the chance of prompt hijacking at the orchestration layer, unintended tool usage, or bypass of more appropriate specialized skills.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger keywords include highly generic terms like 'google', 'workspace', 'cli', and 'bug fix', which are ambiguous across many unrelated tasks. In a multi-skill environment this can lead to unsafe or incorrect invocation, causing the agent to select this skill for requests it was not designed to handle and potentially exposing users to unreliable outputs or unintended actions.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The example trigger sentences are built around everyday phrases like 'Help me' and 'I need', which overlap with normal user language and provide little disambiguation. This can train or bias routing systems toward activating the skill on generic requests, reducing control over when the skill is invoked and increasing the risk of incorrect task handling.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger list includes very broad, high-collision terms such as "google", "workspace", and "cli", which can match many unrelated user requests and cause this skill to activate unexpectedly. In an agent environment, over-broad activation can route user tasks into the wrong workflow, leading to misleading outputs, unintended handling of unrelated data, or suppression of a more appropriate skill.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The description says to use the skill when a user asks for broad categories like work-productivity, google, workspace, or a practical workflow, artifact, checklist, analysis, or implementation support. This makes the enablement boundary ambiguous, increasing the chance that the skill is selected for many generic requests outside its intended domain, which can produce incorrect task routing and unsafe overreach in agent behavior.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example trigger phrases are written as broad everyday requests and largely repeat the same generic wording, without demonstrating distinctive conditions for proper activation. This can train routing logic or skill authors toward permissive matching behavior, making accidental invocation more likely and reducing reliability of skill selection.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The default prompt is broad and generic, using common terms like work-productivity, workflow, and practical help without narrow task boundaries. In combination with agent routing, this can cause the skill to be invoked for loosely related requests, increasing the chance of unintended prompt injection exposure, incorrect tool use, or the skill handling tasks outside its intended scope.

Vague Triggers

High
Confidence
97% confidence
Finding
Enabling implicit invocation without strong activation constraints allows the platform to auto-select this skill based on broad semantic similarity rather than explicit user intent. Because the skill description and prompt are themselves broad, this materially increases accidental invocation and expands the attack surface for unsafe delegation, misrouting, and abuse through adversarial phrasing in user requests.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentence is phrased so broadly that ordinary user requests about help, workflows, or setup could unintentionally activate this skill outside its intended scope. In an agent environment, over-broad activation can cause the wrong skill to handle requests, leading to irrelevant actions, unsafe assumptions, or unintended access to productivity-related contexts.

Vague Triggers

Medium
Confidence
92% confidence
Finding
This activation phrase is ambiguous and generic enough to match many unrelated requests, which increases the chance of accidental invocation. Because the skill is framed around work-productivity and Google-style workflows, misfires could route unrelated user tasks into a workflow that makes assumptions about tools, artifacts, or operational steps the user did not request.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.