Back to skill

Security audit

Work Productivity Multi Search Workflow Helper

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-style workflow helper with overly broad activation wording but no executable code, credential use, persistence, or hidden high-impact behavior.

Install only if you want a general workflow helper for multi-search-engine or related productivity skill work. Be aware that its generic trigger words and implicit invocation may make it appear for unrelated search or productivity requests; users or maintainers should narrow those triggers if precise routing matters.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger list includes extremely common terms such as "multi," "search," and "engine," which can cause the skill to activate in many unrelated contexts. Over-broad activation increases the chance that this skill intercepts requests unintentionally, leading to misrouting, prompt-scope confusion, and unsafe application of workflow guidance where it was not requested.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger keyword list includes extremely broad generic terms such as "multi", "search", "engine", and possibly "global" or "supports", which can cause this skill to activate for many unrelated user requests. Over-broad activation can hijack routing, inject irrelevant instructions into unrelated sessions, and degrade safety by making users receive the wrong workflow or bypassing more appropriate specialized skills.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger sentence is so generic that it can match ordinary user requests unrelated to this skill, causing unintended activation. In an agent ecosystem, over-broad routing can misdirect user input, override a more appropriate skill, and expand the chance that the agent follows the wrong workflow on sensitive tasks.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger sentences and keywords are broad enough to activate on generic terms like 'multi', 'search', or 'engine', which can cause the skill to be invoked outside its intended scope. In an agent environment, over-broad activation can lead to inappropriate delegation, confused task routing, and accidental use of this workflow in contexts where it may produce misleading or irrelevant outputs.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases are broad, generic, and partially malformed, which can cause the skill to activate outside its intended scope. In an agent ecosystem, overbroad activation can route unrelated user requests into this workflow, leading to unintended actions, confusing outputs, or misuse of downstream tools under the wrong context.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The description says to use the skill when a user asks for broad categories like work-productivity, multi, search, or engine, without defining exclusion criteria. This ambiguity makes accidental invocation more likely and can cause the agent to apply this skill outside its intended domain, reducing reliability and potentially interfering with safer or more appropriate skills.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

该技能文件为 SKILL.zh-CN.md,全文内容以中文呈现,但文中没有说明这是可选语言版本,也没有向用户提供语言/区域选择机制。按规则,未获用户选择即固定特定语言/locale 可能构成自然语言政策问题。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill description says to use the skill when users mention several broad terms or need "practical workflow, artifact, checklist, analysis, or implementation support," but it does not clearly bound what scenarios are in scope. Ambiguous enablement criteria can cause accidental invocation across many unrelated productivity or search requests, creating misrouting and increasing the chance that the wrong instructions influence the agent's behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The default prompt is extremely broad and generic, combining common productivity terms with an invocation pattern that could match many ordinary requests. This increases the chance of unintended skill activation, causing prompt/context injection into unrelated conversations and potentially steering agent behavior when the user did not explicitly request this skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Enabling implicit invocation without tight trigger constraints allows the platform to auto-activate the skill based on ambiguous matching. In a broadly described productivity skill, this can cause unintended execution paths, overreach into unrelated tasks, and increase exposure to prompt-surface abuse because the skill may be injected into contexts the user did not intend.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The invocation guidance uses ambiguous examples and weak constraints, which makes skill selection unpredictable and easier to trigger from partial phrase overlap. This is dangerous because agent dispatch logic may invoke the skill in situations it was not designed for, leading to incorrect outputs, workflow confusion, and possible mishandling of higher-risk tasks if this skill displaces a safer or more specialized one.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The file is a zh-CN README, but key user-facing content such as the title, demand description, workflow description, keywords, and trigger phrases are presented in English. This can amount to an implicit language choice without user opt-in or justification in the documentation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.