Back to skill

Security audit

Work Productivity Humanizer Remove Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a low-authority workflow helper with no executable code or data-access behavior, though its broad auto-invocation wording could make it trigger more often than intended.

Before installing, consider narrowing or disabling implicit invocation so the skill is used only for explicit humanizer-style workflow requests. The inspected artifacts do not show hidden execution, exfiltration, destructive behavior, credential handling, or privileged persistence.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger sentences are generic and include broad terms like 'help me', 'practical workflow', and common productivity/editing concepts, which increases the likelihood that the skill is invoked for loosely related prompts rather than explicit user intent. In an agent ecosystem, ambiguous activation can cause the wrong workflow to run, leading to misrouting, unexpected behavior, or unsafe chaining with other capabilities.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger phrases are broad enough to match ordinary requests about writing, editing, reviewing, bug fixing, or general productivity, which can cause the skill to activate outside its intended niche. Overbroad activation increases the chance of unintended prompt injection surface and misrouting, especially because the skill is framed as a reusable workflow helper rather than a tightly scoped tool.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The invocation guidance does not define clear boundaries, prerequisites, or exclusion conditions, so an orchestrator or user may invoke the skill for a wide range of loosely related requests. In a skill ecosystem, unclear scope increases unsafe delegation risk and can let the skill intercept prompts it was not designed to handle reliably or safely.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger keywords are extremely broad and include common terms like 'remove', 'generated', 'writing', and 'reviewing', which can cause the skill to activate for many unrelated user requests. This creates routing ambiguity and increases the chance that the agent applies this skill in inappropriate contexts, producing misaligned assistance or bypassing more suitable safeguards.

Vague Triggers

High
Confidence
94% confidence
Finding
The description says to use the skill when a user asks for broad categories like 'work-productivity' or 'needs a practical workflow,' without defining clear scope limits. An ambiguous activation condition can cause the skill to match a wide range of normal requests, leading to over-invocation and incorrect delegation that may interfere with expected policy handling or task selection.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The example trigger sentences are generic and repetitive, and they do not clarify the boundaries of intended use. Without specific positive and negative examples, integrators or routing systems may generalize too broadly, increasing accidental activation and reducing predictability of skill selection.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger keywords are extremely broad (`writing`, `text`, `editing`, `reviewing`, `bug fix`) and overlap with many ordinary user requests unrelated to this skill’s narrow purpose. This can cause unintended activation and route generic writing or editing tasks through a loosely scoped workflow, increasing the chance of prompt/skill hijacking, user confusion, or policy bypass through overmatching.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The description uses broad need-based language such as helping users whenever they need a 'practical workflow, artifact, checklist, analysis, or implementation support,' which is vague enough to match many unrelated tasks. Ambiguous activation conditions increase the attack surface by making the skill eligible in contexts where its instructions were not intended to apply, reducing predictability and safe routing.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The example trigger phrases are generic conversational requests like 'Help me' and 'I need a practical workflow,' which resemble normal user prompts and do not clearly distinguish this skill from general assistance. Such vague exemplars can bias routing systems or maintainers toward overbroad activation, causing the skill to capture unrelated prompts and apply unintended instructions.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The default prompt is phrased with broad, everyday terms such as 'help me' and a wide set of generic productivity concepts, which can cause the skill to trigger in unrelated conversations. Because the skill is positioned for implicit use and its invocation cue is not narrowly scoped, an attacker or normal user input could accidentally or deliberately steer the agent into invoking this skill outside its intended context.

Vague Triggers

High
Confidence
97% confidence
Finding
Enabling implicit invocation without clear activation constraints allows the platform to auto-select this skill based on vague similarity rather than explicit user consent. Combined with the broad productivity-oriented description and prompt, this increases the chance of unintended routing, prompt-surface expansion, and misuse through crafted inputs that opportunistically match the skill.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentences are broad, natural phrases that could match ordinary user requests unrelated to this specific skill. That creates unintended activation risk, causing the agent to invoke this skill in the wrong context and potentially steer users into irrelevant or unsafe workflow behavior without clear user intent.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.