Back to skill

Security audit

Work Productivity Nano Pdf Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This skill is a documentation-style workflow helper with no executable code, but its broad auto-invocation wording may make it appear in unrelated PDF or editing requests.

Install this only if you are comfortable with a broad helper being auto-selected for some PDF, editing, or workflow requests. Maintainers should narrow the trigger language or disable implicit invocation to reduce accidental activation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentences are broad, natural-language phrases that overlap with ordinary user requests, which increases the chance of unintended or silent skill invocation. In an agent environment, overbroad activation can route unrelated tasks into this skill, causing incorrect workflow execution, unnecessary data exposure to the skill context, or bypass of safer/more specific handling paths.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are broad and include common terms such as 'pdf', 'edit', and generic workflow/help wording, which can cause the skill to activate outside its intended scope. In an agent ecosystem, overbroad activation can route unrelated user requests into this skill, producing inappropriate actions, confusing outputs, or unsafe delegation if the skill is later expanded with operational capabilities.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger keyword list is excessively broad and includes generic terms like 'nano', 'pdf', 'edit', 'natural', and 'language', which can cause the skill to activate in many unrelated conversations. Over-broad activation increases the chance of unintended routing, context capture, and interference with more appropriate skills, reducing predictability and potentially exposing users to incorrect workflows.

Vague Triggers

High
Confidence
91% confidence
Finding
The manifest description uses catch-all wording like 'use when a user asks for work-productivity... or needs a practical workflow, artifact, checklist, analysis, or implementation support,' which is so broad that it can match many unrelated user intents. This ambiguity makes the skill selector less reliable and can lead to accidental invocation in contexts outside nano-pdf workflows.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The example trigger phrases are vague and repetitive, and they do not establish a clear invocation boundary for when this skill should be selected. Ambiguous examples train downstream selection behavior toward overly broad matching, which can increase false activations and degrade system safety and usability.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger keywords are overly broad and include common terms like 'nano', 'pdf', 'edit', 'natural', 'language', and 'instructions', which can cause the skill to activate for many unrelated requests. This creates routing confusion and increases the chance that users are pushed into an unintended workflow, producing irrelevant or unsafe assistance in contexts where more specific handling is needed.

Vague Triggers

High
Confidence
94% confidence
Finding
The description states the skill should be used when users ask for broad categories like work-productivity, nano, pdf, or practical workflow support, which is too vague to safely scope invocation. Ambiguous activation criteria can lead to accidental selection of this skill for unrelated tasks, reducing reliability and potentially interfering with safer or more appropriate skills.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The default prompt is vague, marketing-like, and overloaded with broad terms, which can cause the skill to be selected in situations unrelated to its actual safe operating scope. In an agent ecosystem, ambiguous invocation text increases the chance of unintended activation, misrouting user requests, and unsafe reliance on a workflow helper outside its intended domain.

Vague Triggers

Medium
Confidence
92% confidence
Finding
Enabling implicit invocation without tight trigger constraints allows the platform to auto-select this skill based on weak or noisy relevance signals. Because this skill advertises broad productivity and PDF-related help, implicit invocation materially raises the risk of accidental execution in inappropriate contexts, which can lead to incorrect actions, privacy exposure, or user confusion.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger phrases and keywords are broad enough to match ordinary user language such as 'nano', 'pdf', 'edit', or generic requests for a 'practical workflow', which can cause the skill to activate outside its intended scope. This creates routing confusion and may override more appropriate skills, increasing the chance of irrelevant or unsafe task handling because the agent is steered by ambiguous activation logic rather than clear intent.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.