Back to skill

Security audit

Work Productivity Gog Google Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-style workflow helper with broad activation wording but no hidden execution, credential use, persistence, or destructive behavior.

Install only if you want a broad productivity/workflow helper. Because it can be implicitly invoked on common Google or workflow terms, check that it is the intended skill when handling unrelated Gmail, Calendar, Drive, CLI, or bug-fix requests, and review any generated automation before running it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases are generic enough to match ordinary productivity or workflow requests, which can cause the skill to activate outside the user's clear intent. In an agent ecosystem, over-broad invocation increases the chance of inappropriate tool use, unexpected instruction injection into unrelated tasks, or accidental routing to this skill when a safer or more specific workflow should handle the request.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrases are broad, generic, and map to common user requests such as asking for practical workflow help, which can cause the skill to activate outside its intended scope. In an agent environment, this increases the chance of misrouting benign requests into this skill, leading to unintended access to workflow guidance or adjacent operational behaviors the user did not explicitly request.

Vague Triggers

High
Confidence
96% confidence
Finding
The skill description is broad enough to match many ordinary productivity or Google-related requests, which can cause unintended activation. Over-broad routing increases the chance that this skill intercepts prompts outside its intended scope, leading to misapplication, prompt-space collisions with safer or more specific skills, and unpredictable agent behavior.

Vague Triggers

High
Confidence
98% confidence
Finding
The keyword list includes very common terms such as 'google', 'workspace', 'cli', 'gmail', 'calendar', and 'drive' without any scope limit or disambiguation. These everyday terms are likely to trigger on unrelated user requests, creating excessive overlap with many other skills and enabling accidental invocation in contexts the author did not intend.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The example trigger sentences use generic wording like 'help me' and 'I need a practical workflow' while embedding the same broad requirement text, but they do not define clear activation thresholds. This teaches downstream authors or routers to invoke the skill based on vague phrasing, which reinforces accidental matching and expands prompt overlap.

Vague Triggers

Medium
Confidence
94% confidence
Finding
触发关键词包含非常常见的通用词,如“google”“workspace”“cli”“bug fix”,且示例触发句也没有附加足够限定条件,容易在大量无关对话中被误触发。误触发会让该技能在不相关场景下介入,造成错误路由、输出偏题,甚至覆盖更合适技能的处理逻辑。

Vague Triggers

Medium
Confidence
91% confidence
Finding
技能描述将适用范围定义得过宽,覆盖 work-productivity、gog、google、workspace、cli 以及“实用流程、产物、检查清单、分析或实现支持”等宽泛任务类型,但缺少明确边界和不适用条件。这会放大选择器误判概率,使系统把大量边缘或无关请求交给该技能处理,降低可靠性,并可能让本应进入更专业或更安全技能的请求被错误吸收。

Vague Triggers

Medium
Confidence
91% confidence
Finding
The default prompt is broadly phrased and pairs with implicit invocation, which can cause the skill to activate in situations only loosely related to the user's request. That increases the chance of unintended routing, prompt-context pollution, or the skill being invoked for tasks outside its intended scope, especially because the described domain spans many generic work-productivity and workflow requests.

Vague Triggers

High
Confidence
91% confidence
Finding
The trigger sentence is so broad and generic that it can cause the skill to activate for routine user requests unrelated to the intended Google/Gog workflow scope. Overbroad activation increases the chance of prompt/skill hijacking, accidental invocation, and inappropriate access to context or tools in situations where the skill should not run.

Vague Triggers

Medium
Confidence
88% confidence
Finding
An ambiguous trigger sentence that does not clearly define scope can match loosely related requests and route users into the wrong workflow. In an agent setting, this misrouting can propagate incorrect assumptions, cause unnecessary tool use, or expose sensitive workspace-oriented behavior in contexts the user did not intend.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.