Back to skill

Security audit

Work Productivity Multi Search Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with broad activation wording but no hidden, destructive, credential-seeking, or persistent behavior.

Before installing, consider tightening or disabling implicit invocation because generic words like search or engine could route unrelated requests into this helper. The inspected artifact does not contain scripts or credential-handling instructions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger examples are broad, generic, and include common terms like "multi," "search," "engine," and vague request patterns, which can cause the skill to activate outside its intended scope. In an agent environment, overbroad activation can route unrelated user requests into this workflow, leading to unintended actions, confused delegation, or unsafe application of the skill to contexts it was not designed to handle.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger keywords and example invocations are broad enough to activate on generic terms like 'multi', 'search', or 'engine', which can cause the skill to run outside its intended scope. In an agent ecosystem, over-broad activation can misroute user requests, override more appropriate skills, and increase the chance of unintended actions or disclosure through the wrong workflow.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger keyword list includes extremely generic terms like "multi," "search," and "engine," which are common in unrelated requests. This can cause the skill to activate outside its intended scope, leading to inappropriate instruction injection into benign conversations and unreliable agent behavior.

Vague Triggers

High
Confidence
91% confidence
Finding
The description says to use the skill when a user asks for broad concepts like work-productivity, multi, search, or engine, without strong constraints. Ambiguous activation criteria increase the chance of accidental invocation, which can override better-matched skills or steer the assistant into irrelevant workflows.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The example trigger phrases are written in generic everyday language and mirror broad user requests rather than precise activation examples. These examples may train or encourage overly permissive matching, increasing accidental activation frequency.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger list includes very broad everyday terms such as “multi”, “search”, and “engine”, which can cause the skill to activate for many unrelated user requests. Over-broad triggering can route conversations into an unintended workflow, creating prompt-scope confusion and increasing the chance that the agent applies the wrong instructions or exposes irrelevant capabilities.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The description says the skill should be used whenever users ask for broad categories like work-productivity, multi-search-engine, multi, search, or engine, without defining boundaries or exclusions. This ambiguity makes accidental invocation likely and can cause the agent to select this skill in contexts where it is not appropriate, reducing reliability and potentially interfering with safer or more relevant skills.

Vague Triggers

High
Confidence
95% confidence
Finding
The default prompt contains a very broad natural-language trigger phrase ('Use $work-productivity-multi-search-workflow-helper to help me...') tied to generic work/productivity and search-related wording. In combination with agent ecosystems that support automatic routing, this can cause unintended invocation during ordinary user requests, exposing the skill in contexts the user did not explicitly choose and increasing the chance of prompt-scope confusion or misuse.

Vague Triggers

High
Confidence
98% confidence
Finding
Enabling implicit invocation without clear trigger constraints allows the platform to auto-select this skill based on broad semantic matches rather than explicit user intent. Because this skill is framed around common workplace tasks and generic 'multi-search' workflows, the context makes accidental activation more likely, which can lead to unauthorized tool use, confusing outputs, or unsafe delegation across many normal conversations.

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger phrase is so generic that it can activate on ordinary user language unrelated to the intended skill, causing accidental routing or invocation. In an agent ecosystem, over-broad activation can misapply workflows, leak contextual data to the wrong skill, or let a skill capture requests beyond its intended scope.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The activation guidance is ambiguous because it relies on partial contextual wording rather than clear eligibility criteria, so nearby text may spuriously match. This increases the chance of unintended invocation, especially in multi-skill environments where overlapping prompts compete, reducing reliability and potentially exposing user context to an unnecessary skill.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.