Back to skill

Security audit

Work Productivity Gog Google Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a lightweight workflow-helper skill with overly broad activation wording, but it does not contain code, credential use, persistence, or hidden actions.

Before installing, understand that this skill may be invoked for broad productivity or Google Workspace wording even though it only provides generic workflow/checklist help. Use explicit skill invocation when possible, and do not rely on it for direct Gmail, Calendar, Drive, or Contacts automation without separately reviewing any tool permissions used by the host agent.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrases are generic enough to match ordinary user requests about productivity, workflows, bug fixes, or Google Workspace, which can cause the skill to activate outside its intended scope. Over-broad activation increases the chance of prompt hijacking at the routing layer, unintended data exposure to the skill, or interference with other more appropriate skills.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are broad enough to match common productivity requests such as asking for help with workflows, bug fixes, or setup hardening. This can cause the skill to activate in contexts the user did not explicitly intend, increasing the chance of inappropriate tool use, confusing delegation, or accidental exposure of workspace-related actions in a broad Google/CLI context.

Vague Triggers

High
Confidence
94% confidence
Finding
The skill description is so broad that it can match many ordinary requests involving work productivity, Google, CLI, or workflow help, causing the skill to activate outside its intended niche. Over-broad routing increases the chance that this skill intercepts unrelated tasks, overrides more appropriate skills, and expands the attack surface for prompt-level misuse or unsafe guidance.

Vague Triggers

High
Confidence
97% confidence
Finding
The keyword list contains highly generic terms such as 'google', 'workspace', 'cli', 'gmail', 'calendar', and 'drive', which are common across many unrelated user requests. This ambiguity can cause accidental invocation, skill shadowing, and misrouting of sensitive productivity tasks into a loosely scoped workflow helper, increasing the chance of incorrect actions or unsafe downstream handling.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger list includes very broad, high-collision terms such as "google", "workspace", and "cli", which are likely to appear in many unrelated user requests. This can cause the skill to be invoked outside its intended scope, leading to incorrect routing, unexpected context injection, or overshadowing of more appropriate skills.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description says it should be used whenever a user mentions broad categories like work-productivity, google, workspace, or cli, or whenever they need a practical workflow or analysis. This activation boundary is so wide that the skill may match many unrelated tasks, increasing the chance of accidental invocation and misapplication.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The default prompt trigger phrase is extremely broad and includes common terms like work productivity, workflow, and practical help, which can cause the skill to be invoked during ordinary user requests that were not intended for this skill. Because implicit invocation is enabled, this increases the chance of unintended routing and prompt-surface expansion, letting the skill influence unrelated conversations or analyses.

Vague Triggers

High
Confidence
92% confidence
Finding
The trigger sentence begins with a very broad everyday phrase ('Help me') and then appends requirement text, which can cause the skill to activate for many unrelated user requests. In an agent environment, over-broad invocation increases the chance of unintended routing, causing the wrong skill to handle sensitive productivity or Google Workspace tasks and potentially produce unsafe or irrelevant actions.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger sentence is ambiguous because it maps a generic request for 'a practical workflow' to a long requirement description rather than a clearly bounded task or tool scope. This can cause misclassification of user intent and accidental invocation in contexts far beyond the intended Google/Gog workflow helper use case, reducing safety and reliability of agent behavior.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.