Back to skill

Security audit

Work Productivity Multi Search Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with no hidden commands or data access, though its automatic invocation scope is broader than ideal.

Before installing, be aware this skill may activate for broad search or productivity wording because implicit invocation is enabled and the trigger list includes generic terms. It does not appear to install software, read private data, use credentials, or run commands on its own.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (13)

Vague Triggers

High
Confidence
94% confidence
Finding
The documented trigger phrases are very broad and include generic terms like "multi," "search," "engine," and common help-seeking phrasing. In agent-routing systems, this can cause the skill to activate for unrelated user requests, leading to unintended instruction injection, workflow hijacking, or misapplication of the skill in contexts where it was not requested. The skill context makes this more dangerous because it is positioned as a general productivity helper, increasing the chance of overlap with ordinary user traffic.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger phrases are broad, generic, and include common terms like 'multi', 'search', 'engine', and general help requests, which can cause the skill to activate for unrelated user prompts. In an agent ecosystem, this creates unsafe routing behavior: the wrong skill may intercept requests, produce irrelevant actions, or override more appropriate skills, reducing reliability and potentially causing unintended downstream operations.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger keyword list includes extremely generic terms such as "multi", "search", "engine", "global", and "supports", which are likely to match many unrelated user requests. In an agent skill-routing context, this can cause unintended invocation, prompt collisions, and inappropriate application of the skill's workflow to tasks outside its intended scope, reducing reliability and potentially interfering with safer or more relevant skills.

Vague Triggers

High
Confidence
91% confidence
Finding
The description says to use the skill when a user asks for broad categories like "work-productivity" or needs a "practical workflow, artifact, checklist, analysis, or implementation support," which are common across many unrelated tasks. This vague invocation criteria increases the chance of overmatching and misrouting, causing the skill to activate in contexts where it is not appropriate and potentially displacing more specialized handling.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The example trigger phrases are written in highly generic, natural language and repeat broad demand text rather than precise invocation patterns. These examples may train or bias routing systems toward matching ordinary requests, increasing accidental activation and creating noisy skill selection behavior.

Vague Triggers

High
Confidence
96% confidence
Finding
触发关键词包含“multi”“search”“engine”等极其常见且语义宽泛的词,容易在大量无关请求中误触发该技能。误触发会让代理把不相关任务路由到此技能,导致结果偏题、错误自动化决策,甚至覆盖本应由更合适技能处理的请求。

Vague Triggers

Medium
Confidence
89% confidence
Finding
技能描述中的适用条件覆盖面很大,如“practical workflow, artifact, checklist, analysis, or implementation support”几乎可套用于多类请求,但缺少明确排除条件。这样的边界模糊会降低路由准确性,使系统在相邻主题间发生误选,影响输出可靠性和可预测性。

Vague Triggers

Medium
Confidence
91% confidence
Finding
示例触发句几乎只是重复需求文案,没有展示清晰的命中条件,也没有给出不会触发的反例。缺少正反边界会让调用方或上层路由器难以学习正确使用模式,从而增加错误调用和行为漂移的概率。

Natural-Language Policy Violations

Medium
Confidence
83% confidence
Finding
该技能文件整体以中文编写,但元数据和用途面向更广泛用户,未说明是否支持其他语言或如何根据用户语言切换。虽然这不是传统安全漏洞,但会造成误用、理解偏差和错误执行,特别是在自动路由或多语言环境中可能降低可操作性与结果准确度。

Vague Triggers

Medium
Confidence
91% confidence
Finding
The default prompt uses a very broad natural-language trigger tied to common work-productivity and search-related requests, which can cause the skill to activate in situations the user did not explicitly intend. This increases the risk of prompt hijacking of unrelated conversations, accidental invocation, and unexpected exposure of the skill's behavior in benign contexts.

Vague Triggers

Medium
Confidence
95% confidence
Finding
Enabling implicit invocation without a tightly scoped trigger definition allows the platform to auto-select this skill for a wide range of ordinary requests related to productivity or search workflows. In this skill's context, the broad description and prompt make misrouting more likely, which can lead to unauthorized or confusing activation and increases the attack surface for prompt-based abuse.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger sentence begins with a very broad everyday phrase ('Help me'), which can cause the skill to activate for many unrelated user requests. In an agent-routing context, overly broad triggers increase the chance of unintended invocation, confusing task selection, and misapplication of the skill to contexts it was not designed to handle.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger sentence is ambiguous and underspecified, so it does not clearly constrain when this skill should be selected. Ambiguous routing text can cause the agent to invoke this skill for loosely related productivity or workflow requests, reducing reliability and potentially exposing users to incorrect guidance or unintended processing paths.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.