Back to skill

Security audit

Work Productivity Gog Google Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overly broad activation wording but no hidden code, credential use, persistence, or data access.

Before installing, consider narrowing or disabling implicit activation so this helper only runs for explicit Gog-style workflow assistance. The inspected artifact appears safe as a guidance skill, but its broad keywords may make it show up for unrelated Google Workspace, CLI, or bug-fix requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger sentences are generic and closely resemble normal user requests, which increases the likelihood that the skill will be invoked unintentionally in unrelated contexts. In an agent ecosystem, overbroad activation can route user data or actions into the wrong workflow, causing unintended operations, confusion, or unsafe automation when the skill touches productivity tools such as Google Workspace.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger examples are broad natural-language phrases that can easily appear in ordinary user requests, increasing the chance of accidental skill invocation. In an agent ecosystem, unintended invocation can route user data or actions through the wrong workflow, causing confusion, overreach, or unsafe execution in contexts the user did not explicitly intend.

Vague Triggers

High
Confidence
96% confidence
Finding
The skill description is broad enough to match many ordinary productivity and Google-related requests, which can cause unintended invocation outside the author's intended scope. Over-broad routing increases the chance that this skill intercepts unrelated tasks, influencing agent behavior and potentially bypassing more appropriate or safer specialized skills.

Vague Triggers

High
Confidence
98% confidence
Finding
The keyword list uses high-collision terms such as 'google', 'workspace', 'cli', 'gmail', 'calendar', and 'bug fix', all of which appear in a wide range of benign user requests unrelated to this skill's actual purpose. In agentic systems, such vague triggers can cause prompt-routing hijacks or accidental tool selection, creating reliability and security issues through inappropriate skill activation.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The example trigger sentences train activation behavior around ambiguous, catch-all phrasing rather than demonstrating clear boundaries. This reinforces overmatching and makes it more likely that the skill will be invoked for loosely related requests, reducing routing integrity and increasing the chance of unsafe or irrelevant responses.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger list includes broad generic terms such as "google", "workspace", and "cli", which can match many unrelated user requests and cause this skill to be invoked outside its intended scope. Over-broad activation increases the chance of inappropriate routing, misleading automation, or accidental exposure of workflow guidance in contexts where a different skill should handle the task.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The description says to use the skill when a user asks about broad categories like work-productivity, google, workspace, or cli, or when they need almost any practical workflow or analysis support. This boundary is too vague, making the skill eligible for a wide range of unrelated requests and increasing the risk of accidental invocation and incorrect task handling.

Vague Triggers

Low
Confidence
88% confidence
Finding
The example trigger phrases are highly generic and all positive, with no contrasting negative examples or disambiguation guidance. This can train routing behavior toward over-selection of the skill, especially for loosely related requests mentioning productivity or workflow hardening.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The default prompt trigger phrase is extremely broad and overlaps with common user language such as 'help me' and generic productivity terms. Combined with allow_implicit_invocation: true, this increases the chance the skill is invoked unintentionally during normal conversation, which can cause prompt-routing hijacks, unexpected behavior, or accidental exposure of the skill’s instructions in unrelated contexts.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger sentences are written in broad, natural language that overlaps with ordinary user requests, which can cause the skill to activate when the user did not specifically intend to invoke it. In an agent ecosystem, unintended invocation can route tasks into the wrong workflow, causing data exposure to an unnecessary skill, incorrect actions, or user confusion about why the skill was selected.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The keyword list includes highly generic terms such as 'google,' 'workspace,' 'cli,' and 'bug fix,' which are common across many unrelated tasks. This increases the chance of accidental matching and overbroad routing, especially in automated skill-selection systems that rely on keyword heuristics.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.