Back to skill

Security audit

Work Productivity Humanizer Remove Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-style workflow helper with no executable code or hidden data access, though its triggers are too broad and could activate unexpectedly.

Install only if you want a general workflow helper for Humanizer-style productivity and skill-authoring tasks. Be aware it may be invoked for ordinary writing, editing, review, or bug-fix requests unless the platform or user narrows invocation behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

High
Confidence
90% confidence
Finding
The trigger sentences are broad enough to match many ordinary user requests, which can cause the skill to activate outside its intended scope. In an agent ecosystem, this increases the chance of unintended invocation, priority hijacking, and accidental application of this workflow to unrelated tasks, reducing user control and potentially interfering with safer or more relevant skills.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are broad and generic enough to match ordinary writing, editing, reviewing, and bug-fix requests that are not specifically about this skill’s intended workflow. That can cause accidental invocation, leading the agent to apply unintended instructions or workflow behavior in unrelated contexts, which increases the attack surface for prompt-routing mistakes and skill misuse.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger keywords are extremely broad and include common terms like "writing," "text," "editing," and "reviewing," which can cause this skill to activate for many unrelated user requests. In an agent environment, that creates routing collisions and unintended invocation, increasing the chance that users receive off-target workflow guidance instead of the correct skill behavior.

Vague Triggers

High
Confidence
93% confidence
Finding
The description uses broad, ambiguous activation language such as "Use when a user asks for work-productivity... or needs a practical workflow, artifact, checklist, analysis, or implementation support," which matches a very large share of ordinary requests. This makes the skill prone to accidental selection, reducing reliability and potentially overriding more appropriate skills in mixed-skill systems.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The example trigger sentences are generic and mirror everyday help requests, which trains or encourages broad matching behavior. That increases accidental invocation and skill collision risk, especially because the examples do not demonstrate unique, high-precision phrasing for this specific skill.

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger keyword list is overly broad and includes generic terms like writing, text, editing, reviewing, and bug fix. This can cause the skill to activate for many unrelated user requests, leading to inappropriate routing, unexpected behavior, and possible bypass of safer or more relevant skills in the system.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example trigger phrases use vague, everyday language and do not establish clear boundaries for when the skill should or should not activate. In practice, this increases accidental invocation and prompt-routing ambiguity, which can misdirect sensitive user tasks into an ill-fitting workflow.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The default prompt is broadly worded and includes many generic terms and actions, which can cause the skill to activate in contexts that were not specifically intended by the user. This increases the chance of prompt hijacking, unintended delegation, or the skill being pulled into sensitive conversations where its guidance is irrelevant or unsafe.

Vague Triggers

Medium
Confidence
96% confidence
Finding
Enabling implicit invocation without tight contextual boundaries allows the platform to call this skill automatically based on loose similarity matching. Because the skill description and prompt are broad, this can cause unintended activation in unrelated tasks, exposing users to incorrect automation paths, context leakage, or unsafe actions taken without clear user consent.

Vague Triggers

Medium
Confidence
92% confidence
Finding
Overly broad trigger sentences can cause the skill to activate in contexts unrelated to its intended function, effectively expanding its operational scope without clear user intent. In an agent environment, this can route unrelated prompts into the wrong workflow, causing unsafe assumptions, misleading outputs, or unintended handling of user data/tasks.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.