Back to skill

Security audit

Work Productivity Humanizer Remove Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a low-capability workflow/documentation skill, but its broad trigger wording could cause it to activate more often than users expect.

Install only if you want a general helper for Humanizer-style workflow planning. Be aware that the current trigger terms are broad and implicit invocation is enabled, so a platform may select it for ordinary writing, editing, review, or bug-fix requests unless the publisher narrows the activation wording.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrases are broad, natural-language sentences that can plausibly appear in ordinary user requests, making accidental or over-broad activation likely. This can cause the skill to engage outside its intended scope, introducing unintended workflow changes or misleading outputs when users did not explicitly request this helper.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are extremely broad and include common terms like 'writing', 'text', 'editing', 'reviewing', and 'bug fix', which are likely to match many ordinary requests unrelated to this skill's specific purpose. This can cause unintended auto-invocation, expanding the skill's operational scope and increasing the chance that users are routed into an irrelevant or unsafe workflow without clear intent.

Vague Triggers

High
Confidence
97% confidence
Finding
The skill description is written broadly enough to match many ordinary user requests, which can cause the skill to activate outside its intended niche. Over-broad routing increases the chance of prompt injection inheritance, unintended tool usage, or interference with safer/more specific skills by capturing unrelated tasks.

Vague Triggers

High
Confidence
99% confidence
Finding
The keyword list includes very generic terms such as 'remove', 'signs', 'generated', 'writing', 'text', 'editing', and 'reviewing', which are common across benign conversations. In an agentic environment, this can make the skill over-trigger and hijack unrelated requests, potentially steering user content into a 'humanizer' workflow that may be inappropriate or policy-evasive.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The example triggers are vague and encourage activation from broad phrases like 'Help me' or 'I need a practical workflow,' which provide almost no domain boundary. This trains or signals the routing layer to associate common request phrasing with the skill, increasing accidental invocation and reducing predictability of skill selection.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger keywords include very broad everyday terms such as "writing", "text", "editing", "reviewing", and "bug fix", which can cause the skill to activate for many unrelated user requests. Over-broad activation increases the chance that this skill intercepts conversations outside its intended scope, leading to inappropriate guidance, user confusion, or unintended workflow execution.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill description defines activation using a wide set of loosely bounded conditions, including general topic words and generic requests for workflows, artifacts, checklists, analysis, or implementation support. This unclear boundary makes the routing logic ambiguous, so the skill may be selected for prompts that only weakly relate to its intended job-to-be-done.

Vague Triggers

High
Confidence
93% confidence
Finding
The default prompt embeds a very broad activation phrase covering common concepts like work productivity, practical help, bugs, hardening, and workflow support. In combination with agent routing, this can cause accidental invocation during ordinary user requests, exposing users to unintended skill behavior and making prompt-routing abuse easier.

Vague Triggers

High
Confidence
96% confidence
Finding
Enabling implicit invocation without tight activation constraints allows the platform to auto-select this skill based on ambiguous language. Because the skill description and prompt are broad, this materially increases the chance of unintended execution, incorrect routing, and misuse through prompt injection-like phrasing in ordinary user requests.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger phrases are broad enough to match normal user requests such as generic asks for help, workflows, bug fixes, or editing, which can cause the skill to activate outside its intended scope. In an agent-routing context, this creates prompt-selection confusion and can steer unrelated conversations into this skill, degrading reliability and potentially causing unsafe or unintended handling of user tasks.

VirusTotal

56/56 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.