Back to skill

Security audit

Work Productivity Multi Search Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overly broad activation wording but no executable code, persistence, credential access, or data-moving behavior.

Installers should be aware that the skill may activate too easily for generic search, workflow, or bug-fix requests; it is best used when the user explicitly wants help designing or improving a multi-search-engine style workflow.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger sentences are broad, repetitive, and loosely scoped to generic terms like "multi", "search", and "engine", which can cause the skill to activate in unrelated contexts. In an agent environment, ambiguous activation increases the chance of unintended workflow execution, irrelevant guidance, and unsafe application of the skill to requests the user did not intend to route here.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are broad enough to match ordinary user requests such as generic help with workflows, search, or bug fixing, which can cause the skill to activate outside its intended scope. In an agent ecosystem, this increases the chance of accidental routing, unexpected behavior, and invocation of a workflow the user did not explicitly request.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger list includes highly generic terms like "multi," "search," "engine," and "bug fix," which are common across unrelated user requests. This can cause unintended activation of the skill, routing benign requests into an overly specific workflow and increasing the chance of incorrect behavior or prompt-scope hijacking by simple keyword collisions.

Vague Triggers

High
Confidence
93% confidence
Finding
The manifest description says to use the skill when a user asks for broad concepts like work-productivity, multi, search, or engine, which are far too general for safe routing. In systems that auto-select skills from descriptions, this creates an expansive match surface and can unintentionally invoke the skill for many ordinary conversations.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example triggers use everyday language such as "help me" and "I need a practical workflow," which provides weak disambiguation and reinforces broad matching patterns. These examples may train maintainers or selection systems toward over-activation, especially when combined with already generic keywords and description text.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger keywords include very broad generic terms such as "multi", "search", and "engine", which can match many unrelated user requests and cause unintended activation of this skill. Over-broad routing can misapply the skill’s instructions in irrelevant contexts, increasing the chance of incorrect assistance, workflow interference, or prompt-surface expansion across unrelated tasks.

Vague Triggers

High
Confidence
93% confidence
Finding
The skill description defines activation conditions with a wide and ambiguous scope, including broad categories like work-productivity and search-related requests, without clear boundaries. This can cause the skill to be selected for loosely related prompts, leading to overreach, confusion in agent orchestration, and increased risk of unsafe or irrelevant task handling.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The default_prompt and display text are broad and vague, and the policy explicitly allows implicit invocation. This combination can cause the skill to activate for loosely related user requests, leading to unintended execution paths, user confusion, and accidental exposure of the skill's behavior in contexts where it was not intended.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentence uses a very broad everyday phrase ('Help me ...') that can cause the skill to activate on many unrelated user requests. In an agent-routing context, overbroad triggers can hijack normal conversations, invoke the wrong workflow, and increase the chance that irrelevant or lower-safety instructions are applied in contexts the skill was not meant to handle.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger remains ambiguous because it follows a generic request pattern ('I need a practical workflow for ...') without enough distinguishing context to separate this skill from many other productivity or implementation tasks. This makes misrouting more likely, which can degrade reliability and potentially expose the agent to unintended instruction scopes or outputs that do not fit the user's actual need.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.