Back to skill

Security audit

Work Productivity Gog Google Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a workflow/planning helper with no hidden access or persistence, though its broad trigger wording may make it activate more often than intended.

Install only if you want a general workflow/checklist helper for Gog or Google Workspace-style productivity tasks. Maintainers should narrow the trigger terms or require explicit invocation to avoid accidental activation on ordinary Google, CLI, or bug-fix requests; users should still review any generated scripts or code before running them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are broad, natural-language requests that could match ordinary user prompts and cause the skill to activate unintentionally. Because this skill is positioned around common productivity and Google Workspace tasks, accidental invocation could steer unrelated conversations into this workflow, increasing the chance of inappropriate tool use, data exposure, or confusing agent behavior.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger phrases are so generic that they can match ordinary user requests unrelated to this skill, causing the agent to invoke the skill in unintended contexts. In a workflow/helper skill that touches broad Google Workspace and productivity tasks, over-triggering can lead to misrouting, unnecessary access to sensitive work context, or execution of the wrong workflow when the user did not explicitly ask for it.

Vague Triggers

High
Confidence
96% confidence
Finding
The manifest description contains very broad activation terms like 'google', 'workspace', 'cli', 'analysis', and 'implementation support', which can cause the skill to match many ordinary user requests outside its intended scope. Overbroad routing increases the chance that this skill is invoked when a more appropriate or safer skill should handle the request, leading to unintended prompt capture and confused task execution.

Vague Triggers

High
Confidence
98% confidence
Finding
The trigger keyword list uses ambiguous everyday terms such as 'google', 'workspace', 'cli', 'gmail', 'calendar', and 'bug fix' without qualifiers. These terms are common across many benign requests, so the skill may activate excessively, intercept unrelated tasks, and create routing conflicts with other skills or system behavior.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The example trigger sentences are themselves broad and do not define meaningful activation boundaries, reinforcing a pattern of permissive matching. This can train maintainers or routing logic to treat vague phrases as sufficient for activation, increasing accidental invocation and reducing predictability.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger keywords are extremely broad, including generic terms like 'google', 'workspace', 'cli', and 'bug fix'. This can cause the skill to activate on many unrelated requests, leading to incorrect routing, confused task handling, or accidental invocation in contexts where the skill's assumptions do not apply.

Vague Triggers

High
Confidence
92% confidence
Finding
The description defines activation in vague terms like 'when a user asks for work-productivity, gog, google, workspace, cli, or needs a practical workflow'. Without clear scope boundaries, the skill may match many unrelated conversations and take over tasks outside its intended domain, increasing the chance of unsafe or low-quality assistance.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The default prompt uses a highly generic invocation phrase tied to common productivity terms, which increases the chance of accidental or implicit activation during ordinary user requests. Because implicit invocation is enabled, this broad trigger can cause the skill to run in contexts the user did not clearly intend, potentially injecting its behavior or instructions into unrelated conversations.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentences and keywords are broad enough to match common user requests about work productivity, Google Workspace, Gmail, Calendar, Drive, or bug fixes, which can cause the wrong skill to activate outside its intended scope. In an agent-routing context, this increases the chance of unintended invocation, context confusion, and execution of workflow logic on unrelated tasks.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.