Back to skill

Security audit

Work Productivity Nano Pdf Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overly broad activation wording, but it does not request sensitive access or perform actions on its own.

Before installing, be aware that this skill may activate on ordinary PDF or editing requests because its triggers are broad. It appears safe as a documentation-only helper, but users or maintainers should narrow the triggers if precise skill routing matters.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger examples are broad enough to match many ordinary requests involving PDFs, editing, or generic workflow help, which can cause the skill to activate outside its intended scope. Overbroad activation increases the chance of unintended instruction injection into unrelated conversations, misrouting user tasks, and creating confusing or unsafe agent behavior.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger keywords and sample invocations are broad enough to match many ordinary requests about PDFs, editing, workflows, or general productivity. That can cause the skill to activate outside its intended scope, leading to inappropriate prompt injection into unrelated tasks, user confusion, or unintended handling of sensitive documents in contexts where the user did not explicitly request this skill.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger list is overly broad and includes generic terms like 'nano', 'pdf', 'edit', 'natural', and 'language', which can match many unrelated user requests. This can cause unintended skill activation, routing users into the wrong workflow, and increase the chance that the skill intercepts prompts outside its intended scope.

Vague Triggers

High
Confidence
91% confidence
Finding
The description says to use the skill whenever a user asks for broad topics like work-productivity, nano, pdf, edit, or practical implementation support, without meaningful scoping constraints. This broad invocation language can lead to accidental selection in unrelated contexts and weakens trust in skill routing and least-surprise behavior.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The example trigger phrases are vague, everyday-language invocations that resemble normal conversation rather than precise routing cues. In systems that auto-discover or recommend skills from examples, this can further amplify accidental activation and user confusion.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger list includes very common terms such as "nano", "pdf", "edit", "natural", and "language", which can cause the skill to activate in many unrelated conversations. Over-broad activation increases the chance the agent applies the wrong workflow or injects irrelevant instructions into benign tasks, reducing reliability and potentially affecting downstream security-sensitive operations.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The description says the skill should be used for broad categories like work-productivity, nano, pdf, and edit, but does not clearly define what is in or out of scope. This ambiguity can lead to unintended invocation and confused behavior, especially when similar terms appear in unrelated user requests.

Vague Triggers

High
Confidence
94% confidence
Finding
The default prompt is overly broad and tied to common terms like 'work-productivity,' 'pdf,' and 'analysis,' which can cause the skill to be selected for ordinary user requests beyond its intended scope. This creates prompt-scope confusion and increases the chance of unintended invocation, causing users to receive guidance or workflow behavior they did not explicitly request.

Vague Triggers

High
Confidence
97% confidence
Finding
Enabling implicit invocation without tight trigger constraints allows the platform to activate this skill based on vague matches rather than clear user consent. In combination with the broad prompt wording, this materially raises the risk of unauthorized or surprising activation, which can steer conversations, inject unintended workflow behavior, or override safer/more relevant skills.

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger sentence is excessively broad and can cause the skill to activate for common phrases unrelated to the intended Nano PDF workflow. In an agent environment, overly generic activation increases the chance of unintended routing, causing the wrong skill to handle user inputs and potentially producing unsafe or irrelevant actions under the guise of this workflow helper.

Vague Triggers

Medium
Confidence
90% confidence
Finding
This trigger is ambiguous about when the skill should activate and does not clearly bound its scope to Nano PDF-style workflow requests. Ambiguous activation rules can lead to accidental invocation across unrelated productivity or PDF tasks, reducing reliability and increasing the risk of misapplied automation or disclosure of context to an unintended skill.

VirusTotal

56/56 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.