Back to skill

Security audit

Work Productivity Gog Google Workflow Helper

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only workflow helper with broad activation wording, but no evidence of hidden actions, credential use, persistence, or harmful behavior.

Install only if you want a general workflow/planning helper for Gog-style or Google Workspace productivity tasks. Be aware it may activate on broad Google, workspace, CLI, Gmail, Calendar, Drive, or bug-fix prompts, so disable implicit invocation or invoke it explicitly if your agent supports that control.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger sentences are generic and can activate on broad, loosely related requests involving work productivity, Google, CLI, or bug fixing. In an agent ecosystem, overly broad activation boundaries can cause the wrong skill to run, leading to unintended access to sensitive workflow contexts, unsafe automation steps, or user confusion about which instructions are being applied.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger examples are broad, natural-language phrases that can match ordinary user requests, increasing the chance this skill is invoked when the user did not explicitly intend to use it. In an agent-routing context, overbroad activation can cause prompt/skill hijacking, incorrect tool selection, or unnecessary exposure of user context to a workflow that was not requested.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger keyword list is very broad and includes common terms like "google," "workspace," "cli," and common app names such as "gmail," "calendar," and "drive." This can cause the skill to activate for many unrelated requests, increasing the chance of unintended scope capture, confusing responses, or interference with more appropriate skills.

Vague Triggers

High
Confidence
92% confidence
Finding
The manifest description says to use the skill when a user asks for broad categories like work-productivity, google, workspace, or cli, and for generic needs like a workflow, checklist, analysis, or implementation support. This creates ambiguous activation conditions that can over-match routine requests, leading to unintended invocation and possible misrouting of user tasks.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The example triggers repeat generic phrasing and encourage invocation based on vague references to popularity or practical help rather than clearly bounded technical conditions. This reinforces overbroad matching behavior and can train users or routing systems to invoke the skill in situations where it is not the best fit.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger keywords are very broad and include common terms such as "google", "workspace", and "cli", which can cause the skill to activate for many unrelated requests. In an agent system, this can misroute user tasks, override more appropriate skills, and increase the chance that the skill handles requests outside its intended scope.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The description says to use the skill when users ask about broad categories like work-productivity, google, workspace, or cli, but it does not define clear boundaries for what is in or out of scope. This ambiguity makes skill routing unreliable and can cause accidental invocation on unrelated prompts, which is a security and safety concern in multi-skill agent environments.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The default prompt is broadly phrased and effectively acts as a generic routing instruction for a wide set of topics ('work-productivity, gog, google, workspace, cli'), without clear trigger boundaries or safety constraints. Because implicit invocation is enabled, this ambiguity can cause the skill to activate in unintended contexts, increasing the chance of prompt-scope confusion, over-broad delegation, or misuse of the skill for requests outside its intended domain.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger sentence begins with a highly generic phrase ('Help me ...'), which is likely to collide with many unrelated user requests. In an agent-routing system, this can cause the skill to activate outside its intended scope, leading to incorrect handling of user tasks and increasing the chance that Google Workspace or workflow-related actions are suggested inappropriately.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The phrase 'I need a practical workflow for ...' is also overly broad and resembles normal user language across many benign contexts. Because the rest of the sentence includes requirement boilerplate rather than precise task boundaries, the trigger may spuriously match unrelated conversations, causing misrouting and unreliable agent behavior.

Static analysis

No suspicious patterns detected.