Back to skill

Security audit

Work Productivity Nano Pdf Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a non-executable workflow helper, but its activation wording is too broad and users should invoke it deliberately.

Install only if you want a general workflow helper for Nano Pdf-style productivity tasks. Prefer explicit invocation by skill name, and consider narrowing or disabling implicit invocation so ordinary PDF, editing, or workflow requests are not routed to this skill by accident.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrases are broad enough to match common user language such as asking for help with PDFs or practical workflows, which can cause the skill to activate unintentionally. In an agent environment, overbroad activation can redirect user requests into the wrong workflow, leading to unintended actions, confused delegation, or exposure of user content to a skill that was not explicitly requested.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The invocation guidance mixes broad keywords with ambiguous natural-language examples, making the skill eligible for activation during ordinary conversation rather than only when the user clearly intends to use it. Because this is a productivity/PDF helper skill with wide topical overlap, the context makes accidental activation more likely and increases the chance of misrouting tasks or applying the wrong instructions to user data.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger phrases are broad enough to match ordinary user requests like help with PDFs, editing, or practical workflows, which can cause the skill to activate unintentionally. In an agent ecosystem, overbroad activation can route unrelated tasks into this skill, increasing the chance of incorrect behavior, prompt hijacking through ambiguous invocation, or user confusion about what tool is acting.

Vague Triggers

High
Confidence
98% confidence
Finding
The skill description is broad enough to match many ordinary requests such as 'pdf', 'edit', or general workflow help, which can cause unintended auto-invocation. Over-broad routing increases the chance this skill intercepts unrelated tasks, leading to prompt-scope confusion, misrouting, and possible interference with more appropriate or safer skills.

Vague Triggers

High
Confidence
99% confidence
Finding
The keyword list includes vague, high-collision terms like 'nano', 'pdf', 'edit', 'natural', and 'language' without any scoping constraints. These tokens are common across unrelated conversations, so the skill may activate spuriously and influence conversations it was not intended to handle.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The example trigger sentences demonstrate activation on highly ambiguous phrasing and reinforce broad matching behavior instead of defining safe boundaries. This normalizes imprecise routing and makes accidental invocation more likely, especially in systems that use examples to infer trigger behavior.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger keyword list includes very broad everyday terms such as 'nano', 'pdf', 'edit', 'natural', 'language', and 'instructions', which can cause the skill to activate in many unrelated conversations. Over-broad activation can misroute user requests, inject irrelevant workflow guidance into unrelated tasks, and create opportunities for prompt-space interference when other skills should have handled the request.

Vague Triggers

High
Confidence
92% confidence
Finding
The description says the skill should be used when users ask for broad categories like work-productivity, nano, pdf, or edit, or when they need any practical workflow, artifact, checklist, analysis, or implementation support for the requirement. This activation boundary is too vague and expansive, making accidental invocation likely and increasing the chance that the skill influences prompts outside its intended domain.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The default prompt includes a very broad natural-language trigger phrase ('Use $work-productivity-nano-pdf-workflow-helper to help me ...') tied to generic terms like help, workflow, and productivity-adjacent language. This increases the chance of unintended or implicit invocation during ordinary user conversations, causing the skill to activate outside the user's clear intent and potentially influence responses or workflow behavior unexpectedly.

Vague Triggers

Medium
Confidence
97% confidence
Finding
The trigger phrases are broad, natural-language sentences that overlap with ordinary user requests, which can cause the skill to activate unintentionally outside its intended scope. In an agent ecosystem, overbroad invocation increases the chance of misrouting tasks, unexpected tool usage, and prompt-surface expansion, especially because terms like 'help me' and 'I need a practical workflow' are common across many benign conversations.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.