Back to skill

Security audit

Work Productivity Gog Google Workflow Helper

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only workflow helper with overly broad activation wording, but it does not execute code, request credentials, persist, or access Google services by itself.

Installers should be aware this skill may activate too broadly for routine Google Workspace, CLI, productivity, or bug-fix prompts. It is best used when explicitly invoked for Gog-style workflow planning or checklist generation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill description says to use this skill when a user asks for broad terms like work-productivity, google, workspace, cli, or needs almost any practical workflow, checklist, analysis, or implementation support. That scope is so expansive that the skill can be invoked for many unrelated requests, increasing the chance of misrouting, unexpected tool use, or overshadowing more appropriate specialized skills.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The keyword triggers include highly generic terms such as google, workspace, cli, gmail, calendar, drive, contacts, and bug fix without constraints. These common words can cause accidental activation on a wide range of normal conversations, making the skill act outside its intended domain and potentially exposing users to incorrect guidance or unintended workflow handling.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger sentence begins with a generic helper phrase ('Help me ...') that overlaps heavily with normal user language and is not uniquely tied to this skill. This can cause unintended activation in unrelated conversations, leading the agent to inject workflow behavior or assumptions when the user did not explicitly request this capability.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger sentences are generic and can activate on broad requests involving work productivity, Google Workspace, or bug fixing without clearly constraining scope or user intent. In an agentic environment, this increases the chance of accidental invocation on unrelated tasks, which can cause unintended actions, overbroad access to connected tools, or confusing delegation to the wrong workflow.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad enough to match common productivity or workflow requests, which can cause the skill to activate outside its intended scope. In an agent ecosystem, overbroad routing can misdirect user requests into a workflow with different assumptions, increasing the chance of unintended actions, incorrect guidance, or privilege use tied to Google Workspace-related tasks.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The example trigger sentences use ordinary help-request phrasing like 'Help me' and 'I need a practical workflow', which does not clearly differentiate this skill from general assistant behavior. This increases prompt-routing ambiguity and can cause the skill to be selected for routine requests that do not actually require this specialized workflow helper.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger list is broad and generic, including common terms like 'google', 'workspace', 'cli', 'gmail', and 'calendar'. This can cause the skill to activate for many ordinary requests that are only loosely related, increasing the chance of incorrect routing, unintended instruction injection into unrelated conversations, and user confusion about why this skill was invoked.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The default prompt uses very broad language such as 'help me' combined with common productivity concepts, which can overlap with ordinary user requests unrelated to this specific skill. In combination with implicit invocation, this broad trigger surface makes accidental activation more likely and can cause the skill to intercept benign conversations or influence workflows where it was not intentionally selected.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Enabling implicit invocation without narrowly defined trigger constraints can cause the skill to activate in contexts the user did not intend. Because this skill targets broad workplace themes like productivity, Google, workspace, CLI, and implementation help, ambiguous activation increases the chance of prompt hijacking, unintended tool routing, or accidental exposure of sensitive workflow context to the skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger sentence ('I need a practical workflow for ...') is ambiguous and broad enough to match many legitimate requests outside the intended scope. In an agent environment, such underspecified activation criteria increase the risk of accidental routing, causing irrelevant tool use, confusing outputs, or interference with more appropriate skills.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This file is a zh-CN README, but key operational text and trigger phrases are presented in English, effectively imposing a language format without any opt-in or explanation. Under the language/locale policy rule, forcing or assuming a specific language without user choice can be a policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This is a zh-CN skill file, but the activation examples are written entirely in English and the trigger behavior depends on English phrases such as "Help me" and "I need". That can effectively privilege one language for invocation without clearly offering the user a language or locale choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.