Back to skill

Security audit

Work Productivity Gog Google Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This skill is a documentation-style workflow helper with broad activation wording but no hidden execution, credential use, persistence, or destructive behavior.

Install only if you want a broad productivity workflow helper for Gog or Google Workspace-adjacent tasks. Because implicit invocation is enabled with generic keywords, review whether your agent environment lets you narrow or explicitly invoke the skill to avoid unrelated Google, CLI, or productivity requests being routed here.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger sentence is phrased as a generic help request rather than a narrowly scoped invocation, which increases the chance that unrelated user prompts will activate this skill unexpectedly. In an agent ecosystem, broad triggers can cause prompt-routing confusion, unintentional execution, and make it easier for a malicious user to steer workflows into contexts the skill was not intended to handle.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The invocation guidance is ambiguous because it mixes broad keywords like 'google', 'workspace', and 'bug fix' with generic trigger phrases, without defining strict boundaries for applicability. This can cause accidental selection of the skill for unrelated productivity or Google-adjacent tasks, increasing the risk of incorrect automation behavior and unsafe delegation in multi-skill environments.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrases are generic and overlap with common productivity/help requests, which can cause the skill to activate in situations the user did not intend. In an agent ecosystem, broad activation increases the chance of prompt-routing mistakes, unintended tool usage, or this skill intercepting unrelated workflows involving Google Workspace, CLI, or bug-fix terms.

Vague Triggers

High
Confidence
97% confidence
Finding
The skill description and invocation guidance are broad enough to match many ordinary requests involving Google, workspace, CLI, or general productivity, which can cause inappropriate auto-selection. In an agent system, over-broad routing is dangerous because it can misapply this skill to unrelated tasks, override better-scoped skills, and increase the chance of unsafe or low-context actions being suggested.

Vague Triggers

High
Confidence
99% confidence
Finding
The trigger keywords include very generic terms like 'google', 'workspace', 'cli', 'gmail', 'calendar', and 'drive' without any scoping conditions, making accidental or excessive activation highly likely. In a multi-skill agent environment, this can hijack common user requests, reduce routing precision, and expose users to irrelevant or risky workflow guidance where a more specialized skill should have handled the task.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger keywords are very broad and include generic terms like "google", "workspace", and "cli", which are common in many unrelated requests. This can cause the skill to activate outside its intended scope, creating routing confusion and increasing the chance that users receive irrelevant or unsafe workflow guidance in contexts the skill was not designed for.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The activation condition in the description is vague, stating the skill should be used when users ask about broad categories or need general workflow, analysis, or implementation help. Because the boundaries are unclear, other agents or routing logic may invoke this skill for loosely related tasks, leading to overbroad delegation and unintended handling of user requests.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The default prompt is very broad and overlaps with ordinary productivity/help requests, while implicit invocation is enabled. This can cause the skill to trigger in situations beyond the user's clear intent, increasing the chance of unintended execution, prompt-surface expansion, and misrouting of user tasks to this skill.

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger examples are written as broad natural-language requests that overlap with common user phrasing about workflows, setup help, and productivity. This can cause the skill to activate in situations the user did not explicitly intend, leading to misrouting, overbroad capability exposure, or accidental handling of requests that should go to a narrower or safer skill.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.