Back to skill

Security audit

Work Productivity Gog Google Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This skill is a documentation-style workflow helper with broad activation wording, but it does not install executables, request credentials, persist in the background, or directly access Google Workspace data.

Installers should be aware that this skill may be invoked by broad Google or productivity wording. Review or narrow its trigger terms if you want it to activate only for explicit Gog-style workflow repair, hardening, or skill-authoring requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

High
Confidence
92% confidence
Finding
The trigger phrases are extremely broad and match common, everyday productivity requests, which can cause the skill to activate in contexts far beyond its intended scope. Overbroad invocation increases the chance of inappropriate tool use, user confusion, and accidental routing of unrelated tasks into a workflow that may touch sensitive Google Workspace contexts.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrases are broad enough to match common productivity and Google Workspace requests, which can cause the skill to activate outside its intended scope. In an agent ecosystem, this increases the chance of misrouting user tasks, unintended invocation, and over-application of workflow logic to unrelated requests.

Vague Triggers

High
Confidence
95% confidence
Finding
The skill description and activation guidance are broad enough to match many routine requests involving work, Google, or CLI topics that may not actually need this skill. That can cause unintended invocation, leading the agent to apply irrelevant workflow logic, expose unnecessary context, or crowd out more appropriate skills.

Vague Triggers

High
Confidence
97% confidence
Finding
The keyword triggers are highly generic and ambiguous, especially terms like 'google', 'workspace', 'cli', 'gmail', and 'calendar', which appear in many unrelated user requests. In an agent environment, this increases the chance of accidental skill activation and misrouting, which can degrade decision quality or inappropriately pull this skill into sensitive productivity workflows.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example trigger phrases use very broad natural language that mirrors common everyday requests, so they may teach the router or maintainers to invoke the skill in cases lacking sufficient specificity. This reinforces overmatching behavior and makes accidental activation more likely across normal productivity conversations.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger list includes broad, high-frequency terms such as "google", "workspace", "cli", and "bug fix", which can match many unrelated user requests and cause the skill to activate outside its intended scope. In an agent system, this can hijack routing, override more appropriate skills, and increase the chance that irrelevant workflow guidance is injected into unrelated tasks.

Vague Triggers

High
Confidence
92% confidence
Finding
The frontmatter description says to use the skill whenever a user mentions broad categories like work-productivity, google, workspace, or cli, or when they need almost any practical workflow, checklist, analysis, or implementation help for the requirement. This scope is so expansive that it weakens dispatch precision and can cause the skill to be selected for many generic productivity or Google-related tasks that it was not specifically designed to handle.

Vague Triggers

High
Confidence
95% confidence
Finding
The default prompt includes very broad trigger terms such as 'help me' and generic productivity/workflow language, which can cause unintended invocation in normal user conversations. Because implicit invocation is enabled, this increases the chance the skill activates when not specifically requested, potentially exposing users to unexpected behavior or actions.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger examples use broad natural-language phrasing such as 'Help me...' around generic productivity topics, which can cause the skill to activate when a user did not explicitly intend to invoke it. In an agent environment, overbroad activation increases the chance of unintended routing, context hijacking, or the skill taking over requests better handled by a narrower workflow.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The activation examples are ambiguous and centered on common task wording rather than specific capability boundaries, so unrelated requests may match and invoke the skill. This creates unreliable behavior and can expose users to incorrect automation paths or unnecessary access to a skill with broader operational scope than intended.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.