Back to skill

Security audit

Work Productivity Multi Search Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper; its main issue is overly broad activation wording, not hidden or dangerous behavior.

Before installing, be aware that this skill may be selected too often because its triggers include common search-related words. It appears safe to use, but maintainers should narrow the invocation terms to explicit multi-search workflow requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger sentences and keywords are broad enough to activate on generic terms like "multi," "search," or "engine," which can cause the skill to run outside its intended scope. In an agent environment, overbroad activation can route unrelated user requests into this workflow, leading to confused-deputy behavior, degraded safety checks, or unintended actions based on mismatched context.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrases are broad enough to match ordinary user requests containing common words like 'multi', 'search', 'engine', or generic workflow-help language. This can cause unintended invocation or routing of unrelated requests into the skill, increasing the chance of incorrect tool use, confusing outputs, or privilege overreach in agentic environments.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger keyword list includes extremely broad everyday terms such as "multi", "search", and "engine", which are likely to match many unrelated user requests. This can cause unintended skill activation, leading the agent to apply the wrong workflow or leak irrelevant instructions into unrelated tasks, reducing reliability and potentially steering behavior in unsafe ways.

Vague Triggers

High
Confidence
94% confidence
Finding
The description says to use the skill when a user asks for broad concepts like "work-productivity" or "search," which are common across many benign requests. An ambiguous invocation condition increases the chance of accidental routing, causing the skill to override more appropriate tools or inject irrelevant workflow guidance into unrelated contexts.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The example trigger phrases are generic and paraphrase broad demand statements rather than showing crisp, bounded invocation examples. This makes it harder for an agent or maintainer to distinguish intended activation from ordinary conversation, increasing false positives and workflow confusion.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger list includes very broad common terms such as "multi", "search", and "engine", which can cause the skill to activate in many unrelated conversations. Over-broad activation increases the chance the agent applies this workflow in the wrong context, leading to irrelevant guidance, unintended behavior chaining, or accidental exposure of user context to an inapplicable skill.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The description says to use the skill when a user asks for broad terms like work-productivity, multi, search, or engine, but it does not clearly define boundaries for when the skill should not be used. Ambiguous activation criteria can cause misrouting and accidental invocation, which undermines reliability and may surface inappropriate instructions in unrelated tasks.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The default prompt trigger is broad and phrased in natural language that overlaps with ordinary user requests about productivity, workflows, bugs, or implementation help. Combined with implicit invocation, this can cause unintended activation of the skill during unrelated conversations, increasing the risk of prompt injection propagation, context leakage, or unauthorized tool behavior.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentence is so broad and generic that it can activate on ordinary user phrasing unrelated to this specific skill, causing the wrong skill to run. In an agent environment, over-broad activation can route sensitive or high-stakes tasks into an unintended workflow, creating prompt-routing errors, bad tool selection, and reduced user control.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger description and example activators do not clearly define when the skill should or should not run, which makes accidental invocation likely. Because this is a workflow/helper skill with broad productivity framing, ambiguous activation increases the chance of it intercepting unrelated requests and producing misleading or irrelevant outputs.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.