Back to skill

Security audit

Work Productivity Gog Google Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-style workflow helper with overly broad auto-invocation triggers, but it does not contain code, credential handling, persistence, or automatic external actions.

Install only if you want a general workflow helper for Gog or Google Workspace-style productivity tasks. Be aware that its broad triggers may activate for ordinary Google, Gmail, Calendar, Drive, or CLI requests; confirm the agent is using the right skill before acting on sensitive workspace data or account changes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger sentences are written as broad, natural-language phrases that are likely to appear in ordinary user requests, increasing the chance that the skill is invoked unintentionally. Because the skill targets common work-productivity and Google workflow tasks, accidental activation could steer user interactions into an unintended workflow, causing confusion, misrouting, or execution of the wrong skill path.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrases are broad and overlap with common productivity terms like 'google', 'workspace', 'cli', and generic requests for 'practical workflow'. This can cause unintended invocation in unrelated conversations, leading the agent to activate capabilities or guidance outside the user's actual intent, which is a real safety and reliability issue for skill routing.

Vague Triggers

High
Confidence
96% confidence
Finding
The skill description and activation guidance are broad enough to match many ordinary requests involving 'google', 'workspace', 'cli', or general workflow help, which can cause the skill to activate outside its intended scope. Over-broad routing can lead to inappropriate delegation, context confusion, or unreviewed instructions being applied to unrelated tasks, especially in automated agent selection pipelines.

Vague Triggers

High
Confidence
99% confidence
Finding
The keyword list includes highly generic terms such as 'google', 'workspace', 'cli', 'gmail', 'calendar', and 'drive' without any scope constraints, making accidental or excessive activation likely. In systems that auto-select skills from keywords, this can hijack unrelated user requests and route them through a skill whose instructions were not intended for the task.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The example trigger phrases use broad natural language like 'help me' and 'I need a practical workflow' while embedding the requirement text, but they do not define clear activation boundaries. This encourages ambiguous matching behavior and increases the chance that normal productivity requests are treated as in-scope for this skill when they are not.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger keywords are extremely broad and include common terms like 'google', 'workspace', and 'cli', which can cause the skill to activate in many unrelated contexts. Overbroad activation increases the chance of misrouting user requests, causing unintended skill invocation and unreliable or inappropriate outputs.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The description says to use the skill when users mention broad categories or need generic artifacts like workflows, analysis, or implementation support, but it does not define clear activation boundaries. This ambiguity can cause the skill to be selected for loosely related tasks, reducing safety and predictability of routing.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The example trigger phrases start with generic requests like 'Help me' and 'I need a practical workflow' without contrasting negative examples. This teaches the router that ordinary phrasing is sufficient for activation, which broadens match behavior and can capture unrelated requests.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill enables implicit invocation while providing only a broad, generic trigger description tied to common productivity terms and vague workflow help. This can cause the agent to invoke the skill in situations the user did not clearly intend, increasing the chance of unintended prompt injection exposure, inappropriate data sharing, or execution of actions in the wrong context.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentence is broad enough to match ordinary user phrasing and can cause the skill to activate outside its intended scope. Over-broad invocation conditions increase the chance of inappropriate routing, unintended access to workflow logic, or prompt-surface expansion where the agent applies this skill in contexts the user did not clearly request.

Vague Triggers

High
Confidence
96% confidence
Finding
This trigger is generic and effectively acts as a catch-all for common help-seeking language, which makes accidental or adversarial invocation easier. In an agent ecosystem, that can misroute user requests, override more appropriate skills, and expand the attack surface for prompt injection or unsafe task execution under the wrong workflow assumptions.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.