Back to skill

Security audit

Work Productivity Multi Search Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overly broad activation wording, but no hidden execution, credential access, persistence, or destructive behavior was found.

Install this only if you want a general workflow helper for multi-search-engine-style productivity tasks. The main caveat is accidental activation: the publisher should narrow the trigger terms or disable implicit invocation so ordinary search, engine, or bug-fix requests do not select this skill unexpectedly.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

High
Confidence
91% confidence
Finding
The trigger sentence is phrased as a very common help request, which increases the chance the skill is invoked when a user did not explicitly intend to activate it. In an agent environment, overly broad activation phrases can cause workflow hijacking, misrouting, or accidental execution of instructions in contexts unrelated to this skill.

Vague Triggers

Medium
Confidence
88% confidence
Finding
This trigger pattern describes a generic user request for 'a practical workflow,' without clear boundaries that tie activation to this specific skill. Such ambiguity can lead to unintended invocation and reduce an agent's ability to reliably distinguish between normal discussion and deliberate skill use.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger phrases include extremely generic terms such as "multi", "search", "engine", and broad natural-language examples, which can cause the skill to activate in unrelated contexts. In an agent environment, unintended invocation can misroute user requests, expose the skill in contexts it was not meant for, and create unsafe or unreliable workflow chaining.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger list includes highly generic terms such as "multi," "search," "engine," and "bug fix," which are likely to match many unrelated user requests. This can cause unintended auto-invocation of the skill, leading to prompt-routing confusion, inappropriate workflow injection, or accidental exposure of users to outputs not relevant to their task.

Vague Triggers

High
Confidence
91% confidence
Finding
The manifest description says to use the skill when a user asks for broad concepts like "practical workflow," "artifact," "checklist," "analysis," or "implementation support," which are common across many unrelated tasks. In systems that select skills from descriptions, this ambiguity increases the chance of over-selection and incorrect delegation, reducing reliability and potentially interfering with safer or more appropriate skills.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The example trigger sentences use vague, reusable phrasing and do not show exclusions or disambiguation, reinforcing overly permissive activation behavior. This makes it easier for the skill to be invoked in contexts where it was not intended, especially when examples are used as training or heuristic signals for routing.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger keywords are extremely broad, including generic terms like "multi", "search", and "engine", which can cause this skill to activate for many unrelated user requests. Overbroad activation can route conversations into the wrong workflow, producing irrelevant guidance, interfering with safer or more appropriate skills, and increasing the chance of unintended data handling or confusing automation behavior.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The description says to use the skill when users ask for broad categories like work-productivity or need practical support, but it does not clearly define what requests are in scope versus out of scope. This ambiguity makes accidental invocation more likely and can lead to misrouting, unreliable behavior, and reduced trust in agent decision-making.

Natural-Language Policy Violations

Medium
Confidence
76% confidence
Finding
The skill file is presented entirely in Chinese without indicating language negotiation, fallback behavior, or why this locale-only presentation is required. In a multilingual environment, this can cause user misunderstanding, incorrect execution of the workflow, and operational errors if users or maintainers cannot reliably interpret triggers, constraints, or outputs.

Vague Triggers

High
Confidence
94% confidence
Finding
The default prompt is phrased broadly enough to match common user language about general productivity or search-related help, which can cause unintended or implicit invocation of this skill. Because implicit invocation is enabled, the overlap increases the chance that the agent routes unrelated conversations into this workflow, creating prompt-scope confusion and potentially exposing users to unintended behavior or outputs.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrases are overly broad and closely resemble ordinary user requests, which can cause the skill to activate unintentionally for unrelated conversations. In an agent-routing context, this creates prompt/skill confusion risk: the system may invoke this skill when the user did not intend it, leading to incorrect tool selection, unnecessary disclosure of context to the skill, or unsafe automation chains.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.