Back to skill

Security audit

Work Productivity Multi Search Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a low-risk workflow helper with overly broad activation wording, but it does not install code, request credentials, persist data, or perform hidden actions.

Install only if you want a general helper for multi-search-engine workflow planning. Be aware it may activate on ordinary search or productivity wording unless your agent router requires explicit skill invocation or narrower matching.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger sentences are extremely generic and can match ordinary user requests unrelated to this skill's intended scope. In an agent ecosystem, overly broad activation can cause the wrong skill to auto-invoke, leading to unintended tool use, confusing outputs, or unsafe workflow routing when users did not explicitly request this capability.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The keyword list includes very broad terms like 'multi,' 'search,' 'engine,' and 'integration,' which are common across many benign requests. This creates excessive activation scope and raises the chance that the skill will intercept unrelated tasks, potentially causing mis-execution, privilege overreach, or accidental exposure of this workflow in contexts where it does not belong.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrases are broad generic terms like "multi", "search", and "engine", which can cause the skill to activate in contexts far outside its intended scope. In an agent ecosystem, overbroad activation can route unrelated user requests into this workflow, creating confused-deputy behavior, incorrect tool use, and accidental execution of actions or guidance the user did not intend.

Vague Triggers

High
Confidence
98% confidence
Finding
The trigger keyword list includes extremely generic terms such as "multi," "search," "engine," and "bug fix," which are common in ordinary user requests. This can cause the skill to activate in unintended contexts, increasing the chance of prompt-routing errors, irrelevant skill invocation, and accidental exposure of the skill's behavior where it was not requested.

Vague Triggers

High
Confidence
95% confidence
Finding
The description says to use the skill when a user asks for broad terms like work-productivity, multi, search, or engine, which creates an activation scope far wider than the stated specialized workflow purpose. Overbroad routing criteria can cause accidental invocation on unrelated tasks, reducing system predictability and making policy or capability boundaries easier to bypass through ambiguous wording.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example trigger sentences use very broad natural-language phrasing that could match ordinary conversation rather than an intentional request for this specific skill. Such examples encourage downstream activation heuristics to treat common phrases as invocation signals, which increases false positives and unintended routing.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger keywords include extremely generic terms such as “multi”, “search”, and “engine”, which can match many unrelated user requests. This can cause the skill to activate outside its intended scope, leading to incorrect routing, confusing outputs, and possible overshadowing of more appropriate skills in a larger agent environment.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The description says to use the skill when users ask for broad categories like work-productivity or search-engine help, but it does not clearly define what is in or out of scope. Ambiguous activation criteria increase the chance of accidental invocation and misclassification of requests, reducing reliability and potentially exposing users to irrelevant automation paths.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The example trigger phrases only show positive matches and do not define negative examples or exclusion boundaries. Without contrastive guidance, integrators or routing systems may overgeneralize from the examples and invoke the skill for loosely related prompts, increasing false activations.

Vague Triggers

High
Confidence
90% confidence
Finding
The default prompt uses very broad, everyday trigger terms such as 'help me' and generic productivity/search wording without meaningful boundaries, while implicit invocation is enabled. This can cause the skill to activate in unrelated conversations, creating prompt injection surface, accidental tool routing, and user confusion about when this skill is being applied.

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger phrases are broad, awkwardly templated, and overlap with common language such as 'help me' and 'I need a practical workflow,' which can cause the skill to activate for unrelated requests. In an agent environment, over-broad activation can silently route normal user tasks into this skill, creating prompt-scope confusion, incorrect tool selection, and reduced reliability.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The activation guidance mixes generic keywords ('multi', 'search', 'engine', 'integration') with incomplete trigger sentences, leaving the scope unclear and increasing the chance of accidental invocation. Ambiguous routing logic is dangerous because downstream agents may apply the wrong workflow or produce irrelevant artifacts without the user realizing the mismatch.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.