Back to skill

Security audit

Work Productivity Multi Search Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a low-privilege workflow-helper skill, but its broad trigger words could make it activate more often than intended.

Safe to install if you want a lightweight workflow helper, but be aware it may activate on generic search- or productivity-related requests. Prefer explicit invocation by skill name if your environment supports that.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger sentences are broad enough to match ordinary user requests, which can cause the skill to activate outside its intended scope. In an agent ecosystem, overbroad activation can redirect benign tasks into this workflow unexpectedly, increasing the chance of mis-execution, user confusion, or unsafe chaining with other capabilities.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The invocation guidance mixes a specific command-style activation with ambiguous natural-language examples, leaving the router or user unclear about when this skill should run. That ambiguity increases unintended invocation risk and can make the skill intercept common productivity requests that were not meant for a multi-search-engine workflow helper.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrases are broad and include generic language such as 'Help me' and 'I need a practical workflow', which can cause the skill to activate for unrelated everyday requests. In an agent ecosystem, overbroad activation can route sensitive or irrelevant user tasks into this skill unexpectedly, increasing the chance of unintended prompt handling, workflow confusion, or misuse of downstream tools.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger keyword list includes extremely broad terms such as "multi", "search", "engine", "integration", and "supports", which are common in many unrelated requests. This can cause accidental activation or routing of the skill outside its intended scope, increasing the chance that unrelated tasks are handled by inappropriate instructions and reducing safety predictability.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The description says to use the skill when a user asks for broad categories like work-productivity, multi, search, or engine, without clear boundaries. That loose activation language can over-match routine conversations and lead to unintended invocation, though it does not itself introduce direct code-execution or data-exfiltration behavior.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The example trigger phrases are vague and formulaic, showing the skill can be invoked from very general language rather than a clearly delimited request. In practice, examples like these can train maintainers or routing systems to activate the skill too aggressively, causing misfires and unsafe prompt-surface expansion.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger keywords are overly broad, including generic terms like 'multi', 'search', and 'engine' that commonly appear in unrelated conversations. This can cause the skill to activate outside its intended scope, leading to incorrect routing, user confusion, or unintended execution of workflow guidance in irrelevant contexts.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The description states broad use conditions such as when a user mentions work-productivity, multi-search-engine, multi, search, or engine, but does not clearly define boundaries for when the skill should or should not engage. Ambiguous activation criteria increase the chance of accidental invocation and make it harder to reason about safety and expected behavior.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The default prompt is phrased as a broad, natural-language trigger tied to common productivity and search-related requests, which can cause the skill to activate in situations the user did not explicitly intend. This increases the risk of prompt-surface expansion, unintended tool routing, and accidental exposure of the skill's behavior in unrelated conversations.

Vague Triggers

Medium
Confidence
95% confidence
Finding
Enabling implicit invocation without scoped triggers or exclusions allows the platform to auto-select this skill for a wide range of loosely related requests. In a productivity/search workflow context, that can lead to unintended invocation, override user expectations, and increase the chance that the skill processes inputs outside its intended safety boundaries.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger sentence is broad enough that ordinary user phrasing could accidentally activate this skill outside its intended scope. In an agent-routing context, unintended invocation can cause the wrong workflow to run, leading to irrelevant actions, confusion, or unsafe follow-on behavior if the skill is later extended with more powerful capabilities.

Vague Triggers

Medium
Confidence
91% confidence
Finding
This trigger is ambiguous about when the skill should activate, so the router may match on partial or unrelated language. Because the skill is positioned as a general practical workflow/artifact helper, ambiguous activation broadens its reach and increases the chance of accidental selection over more appropriate skills.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.