Back to skill

Security audit

Work Productivity Multi Search Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-style workflow helper with no executable code, but its automatic activation wording is too broad and could route unrelated requests into the skill.

Before installing, consider narrowing or disabling implicit invocation so ordinary searches or generic workflow requests do not accidentally activate this skill. The artifacts otherwise look like a low-risk planning helper rather than a tool that runs commands or accesses private data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are broad, repetitive, and match generic terms like 'multi', 'search', 'engine', and vague help requests, which can cause the skill to activate outside its intended scope. In an agent environment, overbroad activation can route unrelated tasks into this workflow, leading to incorrect execution, user confusion, or unsafe chaining with other skills.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrases are extremely generic, including common terms like 'multi', 'search', 'engine', and broad request templates. This can cause the skill to activate on ordinary unrelated prompts, leading to incorrect routing, unintended tool/workflow use, and reduced trust in agent behavior; in an agent ecosystem, overbroad invocation is a real security and safety boundary problem.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger keyword list includes extremely generic terms such as "multi," "search," "engine," "integration," and "supports," which are common in unrelated user requests. This can cause the skill to activate outside its intended scope, leading to prompt-routing collisions, inappropriate invocation, and reduced trust in the agent's control flow.

Vague Triggers

High
Confidence
95% confidence
Finding
The manifest description is broad enough to match many routine productivity, workflow, implementation, and analysis requests rather than a tightly scoped skill purpose. In systems that use descriptions for routing or selection, this ambiguity increases the chance of unintended activation and cross-skill interference.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The example trigger phrases are open-ended and effectively restate the broad description instead of showing precise activation conditions. This teaches ambiguous invocation behavior, making it easier for ordinary language to spur accidental routing and making trigger boundaries hard to validate.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger keywords are extremely broad, including generic terms like "multi", "search", and "engine", which can cause the skill to activate on many unrelated requests. This increases the chance of unintended routing, confusing behavior, and accidental invocation in contexts the skill was not designed to handle.

Vague Triggers

High
Confidence
94% confidence
Finding
The activation condition in the description is overly broad and ambiguous, stating the skill should be used whenever users mention common words related to work productivity or search engines. In a dispatch system, this can over-match benign or unrelated requests, leading to incorrect tool selection and unreliable agent behavior.

Vague Triggers

High
Confidence
93% confidence
Finding
The default prompt is extremely broad and includes generic terms like "help me" and a long descriptive phrase that can overlap with ordinary user requests. In systems that support automatic routing or prompt-based skill selection, this can cause unintended invocation, exposing users to the skill when they did not explicitly request it and potentially allowing the skill to influence unrelated workflows.

Vague Triggers

High
Confidence
96% confidence
Finding
Enabling implicit invocation without strong activation constraints allows the platform to auto-select this skill based on weak or ambiguous matches. Combined with the broad prompt language, this increases the chance of unauthorized or surprising execution, which can lead to prompt injection surface expansion, unintended actions, or interference with other skills.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger sentence begins with a very broad phrase ('Help me') that commonly appears in ordinary user requests and is not specific to this skill’s intended scope. This can cause accidental invocation or over-selection of the skill in unrelated contexts, increasing the chance that the agent routes tasks through an irrelevant workflow and produces misleading or unsafe results.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The activation text is still ambiguous because it describes a generic need for 'a practical workflow' without clearly constraining the workflow to multi-search-engine support. Ambiguous routing conditions can cause the skill to be selected for broad productivity requests it was not designed to handle, reducing reliability and potentially bypassing more appropriate specialized skills.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.