Back to skill

Security audit

Work Productivity Humanizer Remove Workflow Helper

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only workflow helper with overly broad activation wording, but no evidence of hidden, destructive, credential-seeking, or exfiltrating behavior.

Before installing, be aware that this skill may activate for broad writing, editing, or bug-fix requests because implicit invocation is enabled and the trigger terms are generic. Install it if you want a general workflow helper for Humanizer-style/generated-text cleanup and related productivity planning; avoid it or narrow its triggers if you need precise routing between specialized skills.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger sentences are broad, natural-language phrases that resemble ordinary user requests rather than deliberate skill-invocation syntax. This can cause unintended activation of the skill in unrelated conversations, leading to misrouting, unexpected workflow execution, or interference with higher-priority instructions.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are broad enough to match ordinary user requests such as writing, editing, reviewing, or bug-fix help, which can cause the skill to activate outside its intended scope. In an agent ecosystem, overly broad routing can lead to misapplication of the skill, unexpected behavior, and increased exposure to downstream unsafe or irrelevant workflow steps.

Vague Triggers

High
Confidence
97% confidence
Finding
The skill description is framed so broadly that it can activate on generic work-productivity, writing, editing, and implementation-support requests unrelated to the specific intended use case. This creates routing ambiguity and increases the chance the skill is invoked inappropriately, causing overreach, policy bypass through misrouting, or unintended handling of sensitive user tasks under an ill-scoped workflow.

Vague Triggers

High
Confidence
98% confidence
Finding
The keyword list includes extremely generic terms such as 'remove', 'generated', 'writing', 'text', 'editing', and 'reviewing' without qualifiers. In a trigger-based skill system, these terms can cause accidental invocation across a large fraction of ordinary user requests, making the skill effectively over-privileged in routing and potentially displacing more appropriate or safer skills.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The example trigger phrases are vague and resemble normal conversational requests, without showing clear boundaries for valid activation. This reinforces ambiguous routing behavior and may train maintainers or automated systems to treat broad, everyday language as sufficient to invoke the skill.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger keywords include very broad everyday terms such as "writing", "text", "editing", "reviewing", and "bug fix", which can cause the skill to activate for many unrelated requests. Over-broad activation increases the chance that this skill intercepts prompts outside its intended scope, leading to user confusion, incorrect workflow application, or unintended handling of sensitive content.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The usage condition in the description is very broad and vague, stating the skill should be used when users ask for certain generic topics or any practical workflow, artifact, checklist, analysis, or implementation support for the requirement. This weak boundary definition can cause accidental invocation in contexts that are only loosely related, reducing predictability and potentially exposing users to irrelevant or unsafe guidance.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The default prompt and description are overly broad and include many generic trigger terms, which increases the chance that the skill is invoked in situations the user did not specifically intend. Because implicit invocation is enabled, this can cause accidental routing to this skill, leading to inappropriate handling of user requests and expanding the skill's operational footprint beyond its intended scope.

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger sentence is broad and can activate on common conversational phrasing rather than a clearly scoped request for this specific skill. That increases the chance of accidental invocation, causing the agent to apply the wrong workflow or expose unrelated user tasks to this skill's behavior.

Vague Triggers

Medium
Confidence
88% confidence
Finding
Although slightly longer, this trigger remains ambiguous because it embeds a large requirement description instead of a precise user intent pattern. Ambiguous routing language can misclassify ordinary requests and invoke the skill in contexts where it was not intended, reducing safety and reliability of agent behavior.

Static analysis

No suspicious patterns detected.