Back to skill

Security audit

Work Productivity Nano Pdf Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overbroad activation wording, but no hidden commands, persistence, credential access, destructive behavior, or data exfiltration.

Install only if you want a general Nano Pdf workflow helper, and be aware it may be selected for ordinary PDF, editing, workflow, checklist, or analysis prompts. The publisher should narrow the trigger terms or disable implicit invocation to reduce accidental activation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

High
Confidence
92% confidence
Finding
The trigger phrases are broad and loosely scoped to common terms like 'pdf', 'edit', and 'workflow', which can cause the skill to activate in situations the user did not intend. In an agent environment, this increases the chance of incorrect routing, unexpected instruction injection into unrelated tasks, or accidental execution of a workflow with different safety assumptions.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger phrases are broad, repetitive, and include generic terms like "nano", "pdf", "edit", and "natural language instructions," which can cause the skill to activate outside its intended context. In an agent ecosystem, overly permissive activation can misroute user requests, invoke the wrong workflow, and increase the chance that unsafe or irrelevant automation is applied to sensitive documents or tasks.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger list includes highly generic terms such as 'nano', 'pdf', 'edit', 'natural', and 'language', which can cause the skill to activate for many unrelated user requests. Over-broad activation increases the chance that this skill intercepts prompts outside its intended scope, leading to incorrect tool selection, user confusion, and potentially unsafe workflow guidance being applied in the wrong context.

Vague Triggers

High
Confidence
93% confidence
Finding
The description says to use the skill for broad categories like 'work-productivity', 'nano', 'pdf', 'edit', or whenever a user 'needs a practical workflow, artifact, checklist, analysis, or implementation support,' which is far too expansive. This ambiguity can cause the orchestrator or agent to select the skill for many ordinary tasks unrelated to the claimed requirement, creating prompt-routing confusion and increasing the attack surface for misuse.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The example trigger sentences are so broad and templated that they do not meaningfully constrain when the skill should run. Poor trigger examples reinforce over-selection behavior and may train maintainers or routing systems to invoke the skill on vague requests, reducing reliability and increasing the likelihood of misapplication.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger list includes very generic terms such as 'nano', 'pdf', 'edit', 'natural', and 'language', which can cause the skill to activate for many unrelated requests. Over-broad activation increases the chance of misrouting user tasks, injecting irrelevant workflow behavior, or overriding a more appropriate skill in contexts the author did not intend.

Vague Triggers

High
Confidence
94% confidence
Finding
The description says the skill should be used when users ask for broad categories like work-productivity, nano, pdf, or practical support artifacts, which is too ambiguous to safely scope invocation. This can make the skill eligible for a wide range of benign everyday requests and lead to unintended execution paths, poor task routing, or interference with more specialized skills.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The default prompt includes very broad activation terms such as 'work-productivity', 'nano', 'pdf', 'edit', 'workflow', 'checklist', and 'analysis', which overlap heavily with ordinary user language. This can cause the skill to be invoked in many unrelated contexts, increasing the chance of unintended prompt injection exposure, irrelevant tool routing, or accidental disclosure of the skill’s instructions into conversations.

Vague Triggers

Medium
Confidence
95% confidence
Finding
Enabling implicit invocation without strict activation constraints allows the system to auto-select this skill based on vague matches rather than deliberate user intent. In this skill, the broad productivity/PDF terminology makes accidental invocation more likely, which expands the attack surface for misrouting, prompt-confusion, and misuse in contexts the skill was not designed to handle.

Vague Triggers

High
Confidence
91% confidence
Finding
The trigger phrases are broad, repetitive, and include generic terms like "nano," "pdf," "edit," and "workflow," which can cause the skill to activate for unrelated requests. Unintended invocation can route users into the wrong workflow, producing irrelevant or unsafe guidance and increasing the chance that this skill handles contexts it was not designed to assess.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.