Back to skill

Security audit

Work Productivity Nano Pdf Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overly broad auto-activation language, but no evidence of hidden code, credential access, persistence, exfiltration, or destructive behavior.

Install only if you want a general workflow helper for Nano Pdf-style PDF workflow adaptation. Be aware it may be selected for broader PDF, editing, or productivity prompts because implicit invocation is enabled and the trigger words are loose; explicit invocation or tighter routing would reduce accidental use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger sentences are highly generic and include common phrases like 'Help me' and 'I need a practical workflow', which can cause the skill to activate for many unrelated requests. In an agent ecosystem, overly broad activation can misroute user tasks, override more appropriate skills, and increase the chance that this skill handles sensitive or unintended workflows without clear user intent.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases are broad enough to match ordinary requests about work productivity, PDFs, editing, or generic workflow help, which can cause the skill to activate when the user did not intend it. In an agent ecosystem, unintended activation can override more appropriate skills, cause prompt-routing errors, and expose users to irrelevant or risky behavior inherited from this skill’s instructions.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger list is overly broad and includes generic terms like "nano," "pdf," "edit," and "natural language," which are likely to match many unrelated user requests. This can cause accidental invocation or routing confusion, exposing users to irrelevant instructions and making it easier for a weakly scoped skill to activate outside its intended context.

Vague Triggers

High
Confidence
97% confidence
Finding
The manifest description says to use the skill when a user asks for broad concepts like work-productivity, pdf, edit, or practical workflow support, which makes the activation boundary ambiguous. In agent systems, this kind of broad routing rule can cause the skill to be selected for many unrelated tasks, increasing the chance of inappropriate guidance, prompt-surface expansion, and interference with more suitable skills.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The example trigger phrases are vague and resemble ordinary help requests rather than clear, distinguishing invocation patterns. This makes misfires more likely during skill selection and reinforces the already broad routing behavior described elsewhere in the file.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger keyword list includes very broad everyday terms such as "nano", "pdf", "edit", "natural", "language", and "instructions", which can cause the skill to activate in many unrelated conversations. Over-broad activation increases the chance that the skill injects irrelevant workflow guidance into contexts where it was not requested, reducing reliability and potentially interfering with higher-priority safety or task-specific behaviors.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The description says the skill should be used whenever the user mentions broad categories like work-productivity, nano, pdf, or edit, without clearly constraining scope. This makes routing ambiguous and can lead to accidental invocation on ordinary productivity or PDF requests that do not match the intended Nano Pdf-style workflow use case.

Vague Triggers

High
Confidence
93% confidence
Finding
The default prompt embeds a very broad activation phrase covering common terms like 'work-productivity', 'pdf', 'edit', 'checklist', 'analysis', and 'implementation support', which can easily match ordinary user requests unrelated to this specific skill. In combination with skill routing, this can cause unintended invocation, injecting the skill's behavior or instructions into unrelated conversations and potentially expanding the attack surface for prompt interference or unsafe workflow execution.

Vague Triggers

High
Confidence
96% confidence
Finding
Enabling implicit invocation without strict activation constraints allows the platform to auto-select this skill based on loosely related user language. Because this skill is described with broad workflow and productivity terms, automatic routing can invoke it in many unintended contexts, increasing the chance of prompt hijacking, mis-scoped actions, or unauthorized influence over conversations where the user did not clearly request this capability.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger sentence is written as a broad, natural-language phrase that overlaps with ordinary user requests, making accidental or unintended skill activation more likely. In an agent environment, overbroad invocation logic can route unrelated PDF or productivity tasks into this skill, causing misexecution, confusion, or unsafe automation paths if the skill then proceeds with assumptions.

Vague Triggers

Medium
Confidence
88% confidence
Finding
This trigger lacks clear boundaries for when the skill should activate, so an orchestrator may interpret many loosely related requests as in-scope. Ambiguous activation increases the chance of incorrect tool selection, which is especially problematic for workflow/helper skills because they may generate actionable plans or edits under the wrong context.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.