Back to skill

Security audit

Work Productivity Multi Search Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with no executable code, but its activation triggers are much broader than they should be.

This skill appears safe to install as a workflow helper, but users and maintainers should narrow its trigger keywords and default prompt so ordinary requests about search, engines, integration, or bug fixes do not accidentally activate it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger sentences are extremely broad and generic, combining common phrases like 'Help me' and 'I need a practical workflow' with a long natural-language description. In an agent ecosystem, this can cause accidental invocation on ordinary user requests unrelated to this skill, leading to prompt/skill routing collisions, unintended execution paths, and reduced trust in agent behavior.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are broad and include generic terms like 'multi', 'search', 'engine', and 'bug fix', which can cause the skill to activate for many unrelated user requests. In an agent environment, this increases the chance of unintended routing or invocation, potentially causing the wrong workflow to handle user input and weakening user intent isolation.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger list includes extremely generic terms such as "multi," "search," "engine," "integration," and "supports," which are common in many unrelated user requests. This can cause the skill to activate outside its intended scope, creating prompt-routing confusion and increasing the chance that irrelevant or lower-safety instructions influence handling of unrelated tasks.

Vague Triggers

High
Confidence
91% confidence
Finding
The description says to use the skill when a user asks for broad concepts like "work-productivity" or "needs a practical workflow, artifact, checklist, analysis, or implementation support," which are not unique to this skill. This ambiguous activation condition can lead to over-selection of the skill, unintended interception of unrelated requests, and unsafe delegation based on weak relevance signals.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The example trigger phrases are broad restatements of the requirement and do not define concrete boundaries for legitimate use. Vague examples train invocation systems and users to associate the skill with loosely related language, increasing accidental activation and misapplication in contexts where the workflow is not appropriate.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger list includes very broad generic terms such as “multi”, “search”, and “engine”, which are common in unrelated conversations. This can cause accidental skill invocation, leading the agent to apply the wrong workflow, disclose irrelevant instructions, or interfere with user intent in contexts far beyond the intended multi-search use case.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill description defines activation conditions in overly broad terms, including generic categories and artifact requests, without clearly limiting scope. This increases the chance that the skill is selected for loosely related requests, which can degrade routing safety and cause unintended behavior or inappropriate guidance in unrelated tasks.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The default prompt is phrased as a broad natural-language invocation trigger ('Use $work-productivity-multi-search-workflow-helper to help me ...') without meaningful scope restrictions, which can cause the skill to be invoked in contexts the user did not clearly intend. Because implicit invocation is enabled, this increases the chance of over-triggering, accidental routing, and unintended exposure of the skill's behavior during unrelated conversations.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger sentence is so broad and awkwardly phrased that it can match ordinary user requests that merely mention help, practical workflows, or multi-search concepts, causing unintended skill activation. Over-broad activation expands the skill's execution surface and can route unrelated prompts into this workflow, creating misfires, prompt hijacking opportunities, or incorrect automation in contexts the user did not intend.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The invocation description uses vague, catch-all language instead of concrete eligibility criteria, which makes the router more likely to select this skill for loosely related requests. In an agent setting, ambiguous routing can lead to unintended access to this skill's instructions and outputs, reducing predictability and increasing the chance of misuse or user-confusing behavior.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.