Back to skill

Security audit

Work Productivity Nano Pdf Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation/workflow helper with no executable code, persistence, credential handling, or hidden data movement, though its automatic activation scope is too broad.

Installers should be aware that this skill may activate for generic PDF or editing requests. It is best used when explicitly asking for Nano Pdf-style workflow hardening, bug-fixing, reliability planning, or related skill-author support.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrase is broad enough to match ordinary user requests about PDFs, editing, or workflow help, which can cause the skill to activate outside its intended niche. Over-broad activation increases the chance of unintended instruction injection into unrelated tasks, misrouting, or unsafe autonomy because the agent may apply this workflow in contexts the user did not explicitly choose.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The invocation guidance does not define when the skill should and should not be used, so a router or user may invoke it for generic productivity or document-editing requests. In agent ecosystems, ambiguous routing materially raises the risk of incorrect tool selection, unintended execution paths, and application of skill-specific instructions in irrelevant or sensitive contexts.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are broad enough to match common terms like 'pdf', 'edit', 'nano', and generic requests for a 'practical workflow', which can cause the skill to activate outside its intended scope. In an agent ecosystem, this increases the chance of unintended routing, privilege misuse, or the skill influencing unrelated user tasks without clear user intent.

Vague Triggers

High
Confidence
96% confidence
Finding
The skill description includes very broad trigger terms such as "nano," "pdf," and "edit," which overlap with common user language and can cause the skill to activate in unrelated contexts. Over-broad activation increases the chance of prompt-routing mistakes, causing the wrong skill instructions to influence responses and potentially bypass safer or more appropriate workflows.

Vague Triggers

High
Confidence
99% confidence
Finding
The keyword list contains ambiguous single words like "nano," "pdf," "edit," "natural," and "language," all of which are common in ordinary requests. This makes accidental invocation likely at scale, which is dangerous because users may unknowingly get routed into this skill's instructions instead of a more suitable capability, creating reliability and security-boundary issues in agent orchestration.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The example trigger sentences use generic phrasing like "Help me" and "I need a practical workflow," without defining what distinguishes valid activation from normal conversation. These examples reinforce loose matching behavior and make implementers more likely to wire the skill to broad natural-language patterns, increasing unintended activation risk.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger list includes very broad everyday terms such as "nano", "pdf", "edit", "natural", "language", and "instructions", which can cause the skill to activate for many unrelated user requests. Over-broad activation increases the chance that the skill intercepts conversations outside its intended scope, leading to unintended behavior, confusion, and possible unsafe handling of tasks the skill was not designed to manage.

Vague Triggers

High
Confidence
93% confidence
Finding
The skill description says to use the skill whenever users mention broad categories like work-productivity, nano, pdf, or edit, or when they need general practical workflows, artifacts, checklists, analysis, or implementation support. This scope is so open-ended that the skill may be selected for many unrelated tasks, undermining routing integrity and increasing the risk of inappropriate or misleading responses.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The default prompt contains broad, everyday trigger terms such as work-productivity, pdf, edit, checklist, and analysis, which can cause the skill to be invoked in many unrelated conversations. That increases the chance of unintended prompt injection surface, accidental tool routing, or the model applying this skill outside its intended scope.

Vague Triggers

Medium
Confidence
94% confidence
Finding
Enabling implicit invocation without tightly scoped activation conditions allows the platform to auto-select this skill based on weak semantic matches. In combination with the broad prompt language, this can cause the skill to activate unexpectedly in unrelated sessions, expanding attack surface and creating opportunities for misapplication or prompt-conflict issues.

Vague Triggers

High
Confidence
91% confidence
Finding
The trigger sentence uses a very broad, everyday phrase ('Help me ...') that can match many unrelated user requests and cause accidental skill invocation. In an agent ecosystem, over-broad routing can expose users to irrelevant automation, increase prompt-surface for unintended behavior, and reduce trust in skill selection.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger description and usage signals are underspecified, listing generic terms like 'nano', 'edit', and 'pdf' without sufficient activation boundaries. This can cause the skill to fire on ambiguous or unrelated requests, leading to misrouting and unintended execution of a workflow the user did not request.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.