Back to skill

Security audit

Work Productivity Nano Pdf Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overly broad activation settings but no hidden code, persistence, credential access, or destructive behavior.

Before installing, consider narrowing or disabling implicit invocation so the skill only runs for explicit Nano PDF workflow requests. The skill appears safe as a local documentation workflow helper, but broad triggers may make it influence unrelated PDF or productivity conversations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger sentences are broad, natural-language phrases that resemble ordinary user requests rather than narrowly scoped invocation patterns. This can cause accidental skill activation in unrelated conversations, leading the agent to apply this workflow when the user did not explicitly intend to use it, which increases the chance of misrouting tasks or exposing workflow-specific behavior unexpectedly.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are broad, generic, and partially natural-language fragments that can match ordinary user requests unrelated to this specific skill. This increases the chance of accidental invocation, causing the wrong skill to activate and potentially leading to irrelevant guidance, workflow confusion, or unintended handling of user content.

Vague Triggers

High
Confidence
97% confidence
Finding
The skill description includes very broad activation terms such as 'work-productivity,' 'pdf,' 'edit,' 'analysis,' and 'implementation support,' which can match a large share of normal user requests unrelated to this specific workflow. Overbroad activation increases the chance the agent invokes this skill in unintended contexts, causing prompt-scope confusion and potentially routing sensitive or safety-relevant tasks through a generic skill with insufficient boundaries.

Vague Triggers

High
Confidence
99% confidence
Finding
The trigger keywords are overly generic—especially 'nano,' 'pdf,' 'edit,' 'natural,' 'language,' and 'instructions'—and are likely to match many unrelated conversations. This creates unsafe auto-selection behavior where the skill may be injected into contexts it was not designed for, degrading task routing and potentially interfering with more appropriate, constrained skills.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The example trigger sentences are vague, repetitive, and not representative of realistic bounded user requests, so they do little to constrain activation. Poor examples can train maintainers or routing systems toward unsafe matching patterns, reinforcing overbroad invocation and increasing accidental use in unrelated tasks.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger keywords include very broad, common terms such as "nano", "pdf", "edit", "natural", and "language", which can match many unrelated user requests. This can cause the skill to activate outside its intended scope, leading to incorrect routing, unexpected behavior, or accidental application of workflow guidance in unrelated contexts.

Vague Triggers

High
Confidence
93% confidence
Finding
The description says to use the skill when users ask for broad topics like work-productivity, nano, pdf, or edit, or when they need general practical workflow or analysis support. This activation logic is overly broad and underspecified, making it likely the skill will be invoked for many unrelated tasks and increasing the chance of confusion, misrouting, or unintended assistance.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The example trigger phrases only show positive examples and do not provide boundary conditions or negative examples to prevent accidental activation. Without counterexamples or explicit limits, downstream routing systems and authors may interpret the skill as applicable to a much wider range of requests than intended.

Vague Triggers

High
Confidence
92% confidence
Finding
The default_prompt is written as a generic invocation phrase with broad natural-language terms like 'help me' and common productivity keywords, which can overlap with ordinary user requests. This increases the chance the skill is invoked unintentionally, causing prompt/context injection into unrelated conversations and creating opportunities for unwanted behavior or data exposure through misrouting.

Vague Triggers

High
Confidence
96% confidence
Finding
Enabling allow_implicit_invocation without tight trigger constraints means the platform may auto-select this skill from loosely related user language. In a broadly described productivity skill, that raises the risk of accidental activation across many benign conversations, potentially exposing user inputs to the skill and letting the skill influence outputs when it was not explicitly requested.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentences are broad enough to match ordinary user requests about PDFs, editing, or practical workflows, which can cause the skill to activate outside its intended scope. Over-broad invocation increases the chance of inappropriate routing, prompt-shadowing of more relevant skills, and accidental execution in contexts where the skill's assumptions or outputs are unsafe or misleading.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.