Back to skill

Security audit

Work Productivity Gog Google Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-style workflow helper with overly broad activation wording, but it does not install code, request credentials, persist, or perform hidden actions.

Before installing, be aware this skill may be invoked for generic Google, workspace, CLI, or bug-fix requests where a narrower skill would be more appropriate. It is otherwise low-risk based on the inspected artifacts; review any generated workflow or code guidance before applying it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are broad enough to match ordinary user requests about productivity, Google Workspace, or bug fixing, which can cause the skill to activate outside its intended scope. Over-broad activation increases the chance of inappropriate routing, unintended data handling, or users receiving actions and guidance from a skill they did not explicitly mean to invoke.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger phrases and keywords are broad enough to match many ordinary requests involving work, Google Workspace, CLI, or bug fixing, which can cause unintended skill activation. In an agent ecosystem, this increases the chance that the skill is invoked in the wrong context, leading to irrelevant actions, prompt-scope confusion, or unsafe delegation when a more specific skill should have handled the request.

Vague Triggers

High
Confidence
97% confidence
Finding
The skill description is broad enough to match many ordinary productivity or Google-related requests, which can cause unintended activation. Over-broad invocation expands the skill’s influence beyond its intended niche and may lead agents to apply irrelevant workflow guidance or bypass more appropriate, narrower skills.

Vague Triggers

High
Confidence
99% confidence
Finding
The trigger keyword list includes highly generic terms like "google," "workspace," and "cli," which are common across many unrelated requests. In an agent-routing context this can cause frequent accidental invocation, misrouting, and over-collection of user context into a skill that was not specifically requested.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The example trigger sentences use generic helper phrasing and repeat broad problem statements without defining clear activation boundaries. This reinforces permissive matching behavior and increases the chance that agents invoke the skill for loosely related requests, reducing routing accuracy and potentially surfacing irrelevant or unsafe guidance.

Vague Triggers

High
Confidence
95% confidence
Finding
触发关键词包含非常通用的词,如“google”“workspace”“cli”“bug fix”,且缺少必须同时满足的上下文约束,容易在与本技能目标无关的普通请求中被误触发。误触发会把用户带入不相关流程、产生错误建议,或让高权限代理在错误场景下执行不必要操作。

Vague Triggers

Medium
Confidence
88% confidence
Finding
技能描述使用了较宽泛的启用条件,如用户提到“work-productivity、gog、google、workspace、cli”或需要“流程、产物、清单、分析”等即可能触发,但没有清楚界定任务边界。这会增加路由歧义,使系统在大量普通生产力或 Google 相关请求上错误启用该技能。

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill enables implicit invocation with no trigger constraints, exclusion conditions, or narrowing logic. This can cause the agent to auto-select the skill in unrelated conversations, expanding the attack surface and increasing the chance of prompt hijacking, unintended tool use, or policy-violating assistance without clear user intent.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The default prompt includes the generic phrase "help me," which overlaps heavily with ordinary user language and makes accidental matching more likely. In combination with a broad productivity/workflow scope, this increases the risk that the skill is invoked in conversations where it was not intended, leading to overbroad behavior and possible exposure to adversarial prompt routing.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger sentence is broad enough to match ordinary user requests about help or practical workflows, which can cause the skill to activate outside its intended scope. In an agent environment, overbroad activation can route unrelated tasks into this skill, leading to confusing behavior, prompt-scope interference, or accidental execution of workflow logic where it does not belong.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The invocation guidance defines activation using loose keywords and generic trigger sentences without clear boundaries, so the skill may be selected for many unrelated productivity or implementation requests. This ambiguity increases the chance of unintended skill invocation, reducing reliability and potentially exposing users to irrelevant instructions or tool-routing errors in multi-skill systems.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.