Back to skill

Security audit

Work Productivity Nano Pdf Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation/workflow helper with no executable code or credential access, though its activation wording is broader than it should be.

Install only if you want a broad Nano Pdf/workflow helper. The publisher should narrow the trigger wording or require explicit invocation to avoid accidental activation on general PDF or editing requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrases are broad enough to match ordinary requests about PDFs, editing, or practical workflows, which can cause the skill to activate outside its intended scope. In an agent ecosystem, overbroad routing can misapply instructions, confuse task selection, and increase the chance that unrelated user inputs are handled by this skill instead of a safer or more appropriate one.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger keywords and example invocations are broad enough to match ordinary user requests about PDFs, editing, workflows, or general productivity, which can cause the skill to activate outside its intended scope. In an agent ecosystem, this creates prompt-routing risk: the wrong skill may intercept benign requests, override more appropriate skills, or inject unintended workflow behavior into unrelated tasks.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger list includes highly generic terms like "nano", "pdf", "edit", "natural", and "language", which are common in many unrelated user requests. This can cause the skill to activate outside its intended scope, increasing the chance of irrelevant behavior, prompt interference, or accidental routing to a skill whose assumptions do not match the user's task.

Vague Triggers

High
Confidence
95% confidence
Finding
The manifest description says to use the skill when a user asks for broad terms like work-productivity, nano, pdf, edit, or any practical workflow/artifact/checklist/analysis support, which is far too expansive. An ambiguous activation condition can make the orchestrator select this skill for many unrelated prompts, leading to misfires, unintended instruction injection into benign tasks, and degraded trust in skill routing.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger list includes very common terms such as "nano", "pdf", "edit", "natural", "language", and "instructions", which are likely to appear in many unrelated user requests. This can cause unintended skill activation, leading the agent to route tasks into this workflow when the user did not intend it, increasing the chance of incorrect handling or prompt-scope hijacking through overbroad matching.

Vague Triggers

High
Confidence
93% confidence
Finding
The description says to use the skill when a user asks for broad categories like work-productivity, nano, pdf, edit, or any practical workflow/artifact/checklist/analysis support for the requirement, which sweeps in a large class of ordinary requests. Such ambiguous invocation conditions make accidental or inappropriate activation more likely, weakening task isolation and making downstream behavior less predictable.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The default prompt includes very broad natural-language terms such as 'help me' and generic productivity/PDF workflow phrasing, which can overlap with ordinary user speech and cause unintended implicit invocation. Because implicit invocation is enabled, the skill may activate when users are not intentionally selecting it, increasing the chance of prompt injection exposure, unexpected behavior, or accidental access to the skill's instructions in unrelated conversations.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentence begins with a very broad everyday phrase ('Help me') and then appends requirement text, making activation boundaries unclear. In agent ecosystems, ambiguous triggers can cause accidental invocation in unrelated conversations, leading to prompt/context hijacking of routing behavior and unintended execution of this skill when the user did not explicitly request it.

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger remains ambiguous because it uses a generic need statement ('I need a practical workflow') tied to copied requirement language rather than concrete activation criteria. This increases the chance that ordinary user requests are misclassified as calls to this skill, which can interfere with agent selection, produce irrelevant behavior, or be abused to steer workflows away from the intended tool.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.