Back to skill

Security audit

Work Productivity Nano Pdf Workflow Helper

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only Nano PDF workflow helper; its main issue is overly broad activation wording, not hidden or harmful behavior.

Install this if you want a general Nano Pdf-style workflow helper. Be aware that its broad trigger terms and implicit invocation may cause it to appear for ordinary PDF, editing, or workflow requests, so confirm it is the intended skill when the task is sensitive or unrelated.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger sentences are broad and closely resemble ordinary user requests for help with PDFs, workflows, or bug fixing, which can cause the skill to activate unintentionally. In an agent ecosystem, overbroad activation can route unrelated conversations into this skill, creating prompt-scope confusion and increasing the chance that the skill handles tasks or data outside the user's actual intent.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases and keywords are broad enough to match common requests such as generic PDF editing, workflow help, or 'natural language instructions,' which can cause the skill to activate outside its intended scope. In an agent ecosystem, overbroad activation can route unrelated user tasks into this skill, increasing the chance of incorrect guidance, prompt collision, or unintended handling of sensitive documents.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger list includes very common terms such as "nano," "pdf," "edit," "natural," and "language," which can cause the skill to activate in many unrelated conversations. Over-broad activation increases the chance the agent applies this skill out of context, creating prompt-routing confusion, unintended instruction injection surface, and reduced reliability of downstream security controls.

Vague Triggers

High
Confidence
90% confidence
Finding
The manifest description says to use the skill when a user asks for broad categories like "work-productivity" or generic artifacts such as a "checklist, analysis, or implementation support." This ambiguous invocation scope can cause inappropriate auto-selection of the skill for unrelated tasks, which weakens isolation between skills and may expose users to irrelevant or conflicting instructions.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The example triggers reinforce vague activation by showing broad natural-language requests without clear boundaries or required context. In systems that learn or match from examples, this can further bias routing toward false activations and increase unintended use of the skill.

Vague Triggers

High
Confidence
94% confidence
Finding
触发关键词包含极其常见且高频的通用词,如“nano”“pdf”“edit”“natural”“language”“instructions”,会与大量普通对话或其他任务重叠,导致技能被过度触发或误触发。误触发会把用户请求路由到不相关的工作流,造成结果偏离、权限边界混淆,甚至让后续自动化步骤在错误上下文中运行。

Vague Triggers

Medium
Confidence
87% confidence
Finding
技能描述中的调用条件使用了宽泛表述,如“当用户提出 work-productivity, nano-pdf, nano, pdf, edit,或需要围绕该需求获得实用流程…时使用”,没有清晰限定任务边界、前置条件或排除情形。这会让编排系统或代理在语义相近但并不适配的场景中调用该技能,增加误用、输出不相关建议以及与其他技能冲突的风险。

Vague Triggers

Medium
Confidence
90% confidence
Finding
The default prompt uses a very broad natural-language trigger phrase ('Use $work-productivity-nano-pdf-workflow-helper to help me ...') tied to generic terms like productivity, pdf, workflow, and help me. This increases the chance of unintended or overly frequent invocation when user text overlaps common speech, which can route tasks into this skill unexpectedly and create prompt-scope confusion or unauthorized tool behavior.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger examples include broad, natural-language phrases such as 'Help me' and 'I need a practical workflow', which are common in ordinary conversations and can cause the skill to activate outside its intended Nano PDF-specific scope. This can lead to unintended routing, inappropriate use of the skill, and reduced trust or safety if users are silently steered into an unrelated workflow.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The activation guidance mixes very generic keywords like 'nano', 'pdf', 'edit', and 'analysis' with broad example sentences, making the trigger boundary unclear. In a routing or auto-selection system, this ambiguity increases the chance of accidental invocation for unrelated work-productivity requests, which can mis-handle user intent and expose downstream workflows to inappropriate inputs.

Static analysis

No suspicious patterns detected.