Back to skill

Security audit

Work Productivity Nano Pdf Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overly broad activation terms, but no code, persistence, credential access, data exfiltration, or destructive behavior was found.

Before installing, consider narrowing or disabling implicit invocation so ordinary PDF, edit, or natural-language requests do not accidentally activate this helper. The skill appears safe as advisory documentation, but its broad triggers may be noisy in a shared skill environment.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrases use broad, everyday wording such as 'Help me' and 'I need a practical workflow', which can cause the skill to activate in contexts far beyond Nano PDF workflow support. In an agent environment, overbroad activation increases the chance of unintended routing, prompt collisions, and misuse of the skill for tasks it was not designed or safety-reviewed to handle.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are broad, generic, and include common terms like "pdf", "edit", and "natural language instructions," which can cause the skill to activate for unrelated user requests. In an agent ecosystem, over-broad routing is a real security and safety issue because it can misapply this skill's workflow to unintended tasks, increasing the chance of incorrect handling, prompt collisions, or unexpected downstream actions.

Vague Triggers

High
Confidence
97% confidence
Finding
The skill description declares activation on very broad terms such as "work-productivity," "nano," "pdf," and "edit," which are common in unrelated requests. This can cause unintended invocation and route users into this skill when they did not ask for it, increasing the chance of irrelevant guidance, policy bypass through misrouting, or interference with more appropriate skills.

Vague Triggers

High
Confidence
99% confidence
Finding
The keyword list includes vague, high-collision words like "nano," "pdf," "edit," "natural," and "language," which are likely to appear in many ordinary conversations. In an agentic environment, such loose matching can trigger this skill unexpectedly and at scale, creating misclassification, workflow confusion, and accidental execution of inappropriate instructions.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The example trigger sentences normalize broad, loosely bounded activation by showing partial natural-language fragments rather than explicit invocation criteria. This reinforces ambiguous matching behavior and makes accidental or inconsistent skill activation more likely, especially when similar wording appears in unrelated user prompts.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger keyword list includes very broad everyday terms such as "nano", "pdf", "edit", "natural", "language", and "instructions", which are likely to appear in unrelated conversations. This can cause the skill to activate outside its intended scope, increasing prompt-routing errors and exposing users to unintended workflow instructions or context mixing.

Vague Triggers

High
Confidence
95% confidence
Finding
The description says the skill should be used when users mention broad terms like work-productivity, nano, pdf, or edit, or whenever they need a workflow, artifact, checklist, analysis, or implementation support. That scope is so open-ended that many unrelated requests could match, making accidental invocation and misrouting materially more likely.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The example trigger phrases are loosely written and closely resemble normal user language, without showing strict constraints or disambiguation signals. This trains downstream routing or authors to accept vague natural-language matches, which can further widen unintended activation.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The default prompt uses a very broad natural-language invocation phrase ('Use $work-productivity-nano-pdf-workflow-helper to help me ...') tied to generic productivity and PDF-related wording. Because implicit invocation is enabled, this increases the chance the skill is triggered by ordinary user phrasing rather than explicit intent, causing unintended prompt injection into unrelated conversations or unexpected execution of the skill's workflow.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger examples are broad, generic phrases that can match ordinary user requests unrelated to this specific skill. In an agent-routing context, this can cause unintended invocation, letting the skill capture traffic outside its intended scope and increasing the chance of irrelevant guidance, workflow confusion, or abuse through prompt steering.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The invocation guidance does not clearly define when the skill should and should not run, so a router or agent may select it for loosely related requests. In a skill ecosystem, ambiguous selection rules expand the skill's effective authority and can be exploited to divert normal requests into this skill's instructions or outputs.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.