Back to skill

Security audit

Work Productivity Humanizer Remove Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overly broad activation wording but no hidden code, persistence, credential use, or destructive behavior.

Install only if you want a general Humanizer-style workflow helper. Expect possible accidental activation on ordinary writing or editing requests unless you invoke skills explicitly or narrow the trigger configuration; no evidence was found of hidden execution, data collection, credential use, or destructive behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger sentence is broad enough to match ordinary user requests about writing, editing, or practical workflows, which can cause the skill to activate outside its intended niche. Over-broad activation increases the chance of unintended routing, confusing outputs, and accidental invocation of a skill that may shape or transform user content when the user did not explicitly request it.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The keyword list and activation examples use generic terms such as 'work-productivity', 'writing', 'text', 'editing', and 'reviewing' without clear guardrails, making the activation scope ambiguous. In an agent ecosystem, this can lead to excessive interception of common tasks, reducing predictability and potentially causing the wrong skill to process sensitive or unrelated user requests.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrases are broad, generic, and likely to match many ordinary user requests unrelated to this specific skill. That can cause accidental invocation of a workflow that rewrites or 'humanizes' content in contexts where it was not intended, increasing the chance of misuse, user confusion, or policy bypass through overbroad routing.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger keywords are extremely broad and include common terms like 'writing', 'text', 'editing', 'reviewing', and 'bug fix', which can cause this skill to activate for many unrelated requests. Over-broad routing increases the chance that users are funneled into an unintended workflow, creating prompt-scope confusion and making downstream misuse or policy bypass easier.

Vague Triggers

High
Confidence
94% confidence
Finding
The manifest description says to use the skill when a user asks for broad categories like 'work-productivity' or general 'practical workflow' help, which is too ambiguous for safe and reliable routing. A vague invocation rule can cause accidental activation across many normal requests, leading to incorrect tool selection and expanding the attack surface for prompt injection through irrelevant contexts.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The example trigger sentences rely on generic language such as 'I need a practical workflow' and repeat broad requirement text without clarifying what uniquely qualifies for this skill. These examples teach routing systems and users to associate common phrasing with activation, which can increase false positives and unintended execution paths.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger keywords include very common terms such as "remove", "generated", "text", "editing", and "reviewing", which can match many ordinary user requests unrelated to this skill. That can cause unintended activation, leading the agent to inject irrelevant workflow guidance or override more appropriate skills, reducing reliability and potentially causing unsafe task routing.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The description says to use the skill when users mention broad terms or need "practical workflow, artifact, checklist, analysis, or implementation support," which is an extremely open-ended enablement condition. This ambiguity expands the activation surface and increases the chance the skill is selected for loosely related requests, causing misrouting and unpredictable behavior.

Vague Triggers

High
Confidence
94% confidence
Finding
The default prompt contains a very broad natural-language trigger phrase tied to common terms like work productivity and humanizer-style workflows, which increases the chance of accidental or implicit invocation during ordinary user conversations. Because implicit invocation is enabled, unrelated requests may route into this skill unexpectedly, causing prompt-scope confusion, unintended behavior, or abuse of the skill in contexts the user did not explicitly request.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger sentences are broad, natural-language phrases that could match routine user requests unrelated to this specific skill, causing unintended activation. In an agent ecosystem, overbroad routing can misapply the skill to unrelated tasks, leading to incorrect actions, confusing outputs, or unsafe workflow substitutions.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger scope is underspecified because it lists broad keywords and example sentences without clear boundaries for when the skill should not run. This increases the chance of accidental invocation on loosely related prompts, which can degrade agent reliability and create unsafe or misleading task selection behavior.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.