Back to skill

Security audit

Work Productivity Humanizer Remove Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a low-risk workflow helper with overly broad activation wording, but it does not run code, request credentials, persist, or access sensitive data.

Installers should be aware that this skill may activate for generic writing, editing, or bug-fix requests because its trigger language is broad. It appears safe from a system-access perspective, but users may want tighter triggers before relying on it in a crowded skill set.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger sentences are written as generic help requests rather than narrowly scoped invocation cues, which increases the chance the skill will activate during ordinary user conversations unrelated to this specific workflow. In an agent environment, unintended invocation can route tasks into the wrong skill, causing confusing behavior, incorrect transformations, or unsafe application of workflow steps outside the user's intent.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The keyword set mixes broad productivity and editing terms like 'writing', 'text', 'editing', 'reviewing', and 'bug fix' with only weak constraints, making the skill eligible for many unrelated prompts. Because this is a workflow helper in a general productivity context, overbroad matching materially raises the risk of accidental selection and execution, which can mis-handle user requests or apply transformations where they were not wanted.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrases are broad enough to match ordinary writing, editing, and workflow-help requests, which increases the chance this skill is invoked unintentionally. Over-broad activation can route unrelated user requests into this skill’s behavior, causing prompt hijacking of task selection, confusing outputs, or accidental use in contexts the skill was not designed to handle.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger keywords are extremely broad and include generic terms like 'writing', 'text', 'editing', 'reviewing', and 'bug fix', which can cause this skill to activate for many unrelated user requests. Overbroad activation increases the chance that the skill intercepts normal productivity or writing tasks and applies behavior outside its intended scope, creating routing confusion and unsafe or unintended assistance patterns.

Vague Triggers

High
Confidence
92% confidence
Finding
The manifest description says to use the skill when a user asks for broad categories like 'work-productivity' or 'needs a practical workflow, artifact, checklist, analysis, or implementation support,' which are common across many benign tasks. This ambiguous 'use when' language makes the activation boundary unclear and can cause the skill to be selected for a wide range of unrelated prompts, undermining predictable skill routing and increasing the risk of misuse or accidental overreach.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The example trigger sentences are generic request templates that can match many ordinary user prompts without establishing distinct routing conditions. Because examples often influence invocation logic or human interpretation, vague examples reinforce the already broad activation scope and make accidental invocation more likely.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger list includes very broad everyday terms such as writing, text, editing, reviewing, and bug fix, which can cause the skill to activate in many unrelated contexts. Over-broad activation increases the chance that the agent applies the wrong workflow, leading to unintended transformations, confusing outputs, or unsafe automation in contexts the skill was not designed for.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill description says it should be used when users mention broad categories or need practical workflow, artifact, checklist, analysis, or implementation support, but it does not clearly define the boundaries of appropriate use. This ambiguity can cause inappropriate invocation across many normal productivity requests, creating routing errors and increasing the risk of irrelevant or disruptive behavior.

Natural-Language Policy Violations

Medium
Confidence
76% confidence
Finding
The file is presented only in Chinese and does not provide a user-choice mechanism for language selection. While not a direct code-execution issue, this can lead to user misunderstanding of scope, triggers, and outputs, which indirectly increases the risk of accidental activation or misuse in multilingual environments.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The default prompt includes broad, common-language trigger terms and is paired with implicit invocation, making it easy for unrelated user requests containing words like 'help' or 'workflow' to activate the skill unexpectedly. This increases the chance of prompt injection, unintended tool use, or scope creep because the agent may invoke the skill outside the user's actual intent.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrases are broad, natural-language sentences and generic keywords such as 'writing', 'editing', 'reviewing', and 'bug fix', which can cause the skill to activate in many unrelated contexts. Unintended invocation can route users into the wrong workflow, leading to confused task handling, policy bypass through incorrect tool selection, or execution of actions the user did not specifically request.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.