Back to skill

Security audit

Work Productivity Multi Search Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with broad activation wording but no hidden execution, data access, persistence, or credential handling.

Installers should be aware that this skill may activate too broadly for generic search, engine, integration, or bug-fix requests. It appears safe from an execution and data-access standpoint, but the publisher should narrow trigger phrases or disable implicit invocation to reduce accidental use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger sentences are so generic that they can match ordinary user requests unrelated to this skill’s intended scope, causing the skill to activate unexpectedly. In an agent ecosystem, broad activation increases the chance of misrouting tasks, overriding more appropriate skills, or injecting this workflow into sensitive contexts where its assumptions or downstream actions may be unsafe.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are broad enough to match normal user language such as 'help me' or generic requests about workflows, search, integration, or bug fixes. In an agent environment, this can cause unintended activation of the skill, leading to prompt/skill hijacking of unrelated tasks, confused routing, and execution of the wrong workflow without clear user intent.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger keyword list includes extremely generic terms such as "multi", "search", "engine", "integration", and "bug fix", which are common in unrelated user requests. This can cause the skill to activate outside its intended scope, leading to incorrect routing, unintended prompt injection surface expansion, and reduced reliability when adversarial or irrelevant inputs are matched.

Vague Triggers

High
Confidence
94% confidence
Finding
The manifest description says to use the skill when a user asks for broad concepts like "work-productivity," "multi," "search," or "engine," which creates ambiguous activation criteria. In an agent environment, overbroad activation can misroute normal conversations into this skill, increasing the chance of unintended behavior, unsafe automation assistance, or interference with more appropriate skills.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The example trigger sentences are vague, repetitive, and not representative of realistic user requests, so they fail to constrain when the skill should run. Poor trigger examples make accidental or overly permissive invocation more likely, which can amplify routing errors caused by the already broad keyword set.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger keywords include very broad everyday terms such as “multi”, “search”, and “engine”, which can match many unrelated user requests. This can cause the skill to activate outside its intended scope, leading to prompt hijacking of routing behavior, user confusion, or unintended handling of unrelated tasks by a workflow that may assume different constraints.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The top-level description defines activation in broad, ambiguous terms and does not clearly distinguish in-scope versus out-of-scope requests. In a skill-routing environment, this increases the chance that unrelated prompts are captured, which can misapply the skill and interfere with safer or more appropriate skills.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example trigger phrases are themselves broad and repetitive, reinforcing permissive matching behavior instead of constraining it. Because examples often guide implementation or downstream routing heuristics, vague examples can operationally expand the trigger surface and increase accidental invocation.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The default prompt is phrased as a broad natural-language invocation and includes generic terms such as 'help me' and common workflow language, which can overlap with ordinary user requests. In combination with agent routing, this can cause unintended activation of the skill, exposing users to incorrect tool selection, prompt hijacking surface expansion, or accidental execution in contexts where the user did not explicitly request this helper.

Vague Triggers

Medium
Confidence
96% confidence
Finding
Enabling implicit invocation without strict trigger constraints allows the platform to auto-select this skill from loosely related user language. Because this skill targets broad productivity and search workflow use cases, the context increases the chance of accidental invocation, which can lead to misrouting, unintended prompt insertion, and increased exposure to adversarial or irrelevant contexts.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger phrases are broad and generic enough to match ordinary user language such as requests for a 'practical workflow' or references to 'search' and 'engine', which can cause this skill to activate outside its intended scope. In an agent environment, overbroad activation can misroute tasks, create prompt-surface confusion, and let irrelevant or lower-safety instructions take precedence over more appropriate skills.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.