Back to skill

Security audit

Work Productivity Multi Search Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overbroad activation wording, but no hidden code, persistence, credential handling, or destructive behavior.

Installers should be aware that this skill may be invoked too broadly for ordinary search or productivity requests. Review or narrow the trigger keywords and implicit invocation settings if precise routing matters. The inspected artifacts otherwise behave like a benign workflow/documentation helper.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger sentences are broad, repetitive, and loosely tied to common terms like 'work-productivity', 'multi', 'search', and 'engine', which can cause the skill to activate in contexts the user did not intend. In an agent ecosystem, ambiguous activation can route unrelated requests into this workflow, increasing the chance of incorrect actions, confusing outputs, or unintended tool use.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrases are extremely broad terms like 'multi', 'search', and 'engine', plus generic help requests, which can cause the skill to activate for many unrelated user prompts. In an agent environment, this can lead to incorrect routing, unintended execution of this workflow, and interference with higher-priority or more appropriate skills.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger keyword list includes extremely generic terms such as "multi", "search", "engine", and "integration", which can match many unrelated user requests and cause unintended invocation. Over-broad activation increases the chance that the skill handles prompts outside its intended scope, creating routing confusion and potentially bypassing more appropriate or safer skills.

Vague Triggers

High
Confidence
90% confidence
Finding
The manifest description uses broad invocation language like "Use when a user asks for work-productivity, multi-search-engine, multi, search, engine" without clearly defining exclusions or context. This can make the skill eligible for unrelated prompts, leading to accidental invocation and unreliable or unsafe task routing.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The example trigger phrases are generic and repetitive, and they do not teach clear activation boundaries to downstream systems or maintainers. This reinforces broad matching behavior and may increase false activations, though the examples themselves are not directly executing code or causing privilege escalation.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger keywords are overly broad, including generic terms like "multi", "search", and "engine", which can cause the skill to activate for many unrelated user requests. In an agent environment, this can misroute tasks, override more appropriate skills, and increase the chance that users receive irrelevant or unsafe workflow guidance outside the intended scope.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The activation description is vague and expansive, saying the skill should be used whenever users mention broad categories or need general workflow, checklist, analysis, or implementation support. This ambiguity makes dispatch decisions unreliable and can cause the skill to be invoked outside its intended domain, reducing safety and correctness.

Natural-Language Policy Violations

Medium
Confidence
82% confidence
Finding
The skill is provided only in a Chinese-language regionalized file without any indication of user language preference handling or fallback behavior. This can lead to misunderstanding of instructions, incorrect execution of workflows, or unsafe assumptions when the agent or end user expects another language.

Vague Triggers

High
Confidence
95% confidence
Finding
The default prompt contains broad, natural-language trigger text such as 'help me' and generic workflow terms, which can cause the skill to be selected in many ordinary conversations that are not clearly requesting this capability. In combination with agent routing, this increases the chance of unintended invocation, prompt-scope confusion, and accidental exposure of this skill's behaviors in contexts where the user did not explicitly ask for it.

Vague Triggers

High
Confidence
97% confidence
Finding
Enabling implicit invocation without strong activation constraints allows the platform to auto-select this skill based on vague similarity, rather than clear user intent. Because this skill is framed around broad productivity and search-workflow assistance, the attack surface is larger: benign user requests may unintentionally activate the skill, leading to misrouting, unexpected actions, or unsafe chaining with other agent capabilities.

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger sentence is so broad and awkwardly phrased that it can match ordinary user requests unrelated to this specific skill, causing unintended activation. Overbroad activation increases the chance the skill intercepts prompts outside its intended scope, which can misroute tasks, surface irrelevant instructions, or interfere with safer/more appropriate skills.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The usage signals and trigger descriptions lack precise boundaries, relying on generic terms like 'multi', 'search', and 'engine' that are common in unrelated contexts. This makes accidental invocation likely and can cause prompt-routing confusion, reducing reliability and potentially exposing users to inappropriate workflow guidance for tasks the skill was not meant to handle.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.