Back to skill

Security audit

Work Productivity Nano Pdf Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a text-only workflow helper with no executable code, but its automatic activation wording is broader than it needs to be.

Before installing, consider narrowing invocation to explicit Nano Pdf workflow requests or disabling implicit invocation to avoid accidental routing for ordinary PDF, edit, or natural-language requests. The inspected artifacts do not show malicious behavior, hidden execution, credential access, persistence, or exfiltration.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are extremely generic and include common terms like "help me," "practical workflow," "pdf," and "edit," which can cause the skill to activate for ordinary unrelated requests. In an agent ecosystem, overly broad activation can misroute tasks, cause unintended execution of this skill's instructions, and reduce user control over which capability is being invoked.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrases are broad enough to match common terms like "pdf", "edit", "natural language", and generic help requests, which can cause the skill to activate outside its intended scope. In an agent ecosystem, overbroad activation can route unrelated user tasks into this skill, leading to incorrect automation, privilege overreach, or accidental processing of sensitive documents under the wrong workflow.

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger list includes very common terms such as "nano," "pdf," "edit," "natural," and "language," which can match many unrelated user requests. This creates a skill-routing vulnerability where the skill may activate unintentionally, causing incorrect handling, prompt-surface expansion, and potential interference with safer or more relevant skills.

Vague Triggers

High
Confidence
90% confidence
Finding
The manifest description says to use the skill when a user asks for broad categories like work-productivity, pdf, edit, or a practical workflow, artifact, checklist, analysis, or implementation support. That wording is so general that many ordinary requests could match, increasing the chance of unintended activation and misrouting.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The example trigger sentences are generic request formulations rather than precise invocation cues, reinforcing broad matching behavior during routing or author reuse. While less severe than the trigger list itself, they normalize accidental activation patterns and make the skill easier to invoke in unrelated contexts.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger list includes very common terms such as 'nano', 'pdf', 'edit', 'natural', 'language', and 'instructions', which can match many unrelated user requests and cause unintended invocation. Over-broad activation increases the chance that this skill hijacks routing from more appropriate skills, potentially leading to incorrect workflow guidance or unsafe actions in contexts the skill was not designed for.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The description says to use the skill whenever users mention broad categories like work-productivity, nano, pdf, or need general workflow/checklist/analysis support, which is ambiguous and far wider than the specific claimed job-to-be-done. This can cause the agent to select the skill for loosely related requests, creating misrouting risk and reducing reliability of downstream task handling.

Vague Triggers

High
Confidence
93% confidence
Finding
The default prompt is written as a very broad natural-language trigger and includes generic terms like 'help me' plus common workflow/productivity language, which can cause unintended invocation in ordinary user conversations. Because implicit invocation is enabled, this increases the chance the skill is selected when the user did not explicitly request it, potentially exposing the user to incorrect automation paths or undesired prompt influence.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger phrases are broad enough to match common terms like "work-productivity," "pdf," "nano," and generic requests for workflows or analysis, which can cause the skill to activate outside its intended scope. Overbroad activation increases the chance of misrouting user requests, unnecessary invocation of this skill, and unintended handling of unrelated tasks, especially in systems that auto-select skills from keyword matches.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.