Back to skill

Security audit

Work Productivity Nano Pdf Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a low-impact workflow/documentation skill, but its activation wording is broad and may trigger on unrelated PDF or editing requests.

Installers should expect a documentation-style helper, not a tool that directly edits PDFs. Consider narrowing or explicitly invoking it when you want Nano Pdf-style workflow help, because the current keywords could make it appear for ordinary PDF, editing, or natural-language requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger keywords and example invocations are broad terms like 'pdf', 'edit', 'nano', and generic workflow/help phrases that overlap with many ordinary user requests. This can cause the skill to activate outside its intended scope, leading to unintended instruction injection into unrelated conversations and increasing the chance of unsafe or confusing behavior across a wide range of benign tasks.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger phrases are broad enough to match common requests about productivity, PDFs, editing, or practical workflows, which can cause the skill to activate outside its intended scope. In an agent environment, overbroad invocation increases the chance of incorrect tool selection, unintended prompt capture, and execution of the wrong workflow for unrelated user tasks.

Vague Triggers

High
Confidence
96% confidence
Finding
The skill description says to use the skill when a user asks for broad terms like 'work-productivity', 'nano', 'pdf', 'edit', or for generic artifacts such as a checklist or analysis. These triggers are not tightly scoped to a specific workflow, so the skill may activate for many unrelated requests and override more appropriate skills or routing logic.

Vague Triggers

High
Confidence
98% confidence
Finding
The keyword list contains highly generic terms such as 'nano', 'pdf', 'edit', 'natural', 'language', and 'instructions', each of which commonly appears in unrelated user prompts. In an agent ecosystem, this can cause unintended invocation, misrouting, and prompt-surface expansion, increasing the chance that this skill handles tasks it was not designed or reviewed for.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The example trigger sentences repeat broad demand language and encourage activation from vague requests instead of demonstrating clear boundaries. This normalizes ambiguous invocation behavior and makes downstream routing or evaluators more likely to treat loosely related prompts as matches.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger keyword list includes very broad, everyday terms such as "nano", "pdf", "edit", "natural", and "language", which can cause the skill to activate in many unrelated conversations. Over-broad activation increases the chance that the agent routes users into an unintended workflow, producing irrelevant guidance or overriding a more appropriate skill, which is a security and reliability concern in agent orchestration.

Vague Triggers

High
Confidence
94% confidence
Finding
The description says to use the skill when a user asks for broad categories like work-productivity, nano, pdf, or edit, without clearly defining boundaries. This weak activation policy can cause accidental invocation on routine requests, increasing misrouting risk and making it easier for unrelated prompts to pull in this skill unexpectedly.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The default prompt contains a very broad natural-language trigger phrase ('Use $work-productivity-nano-pdf-workflow-helper to help me...') tied to generic terms like work-productivity, nano, and pdf. In combination with implicit invocation being enabled, this can cause the skill to activate for ordinary user requests that were not meant to invoke it, creating prompt-scope confusion and increasing the chance of unintended behavior or policy bypass through overbroad routing.

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger examples are broad enough to match ordinary requests about PDFs, editing, workflows, or implementation help, which can cause the skill to activate outside its intended niche. Overbroad activation can route unrelated user tasks into this skill, creating prompt-scope confusion, poor task handling, and increasing the chance that downstream instructions are applied in inappropriate contexts.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The activation scope is ambiguous because the keywords and trigger sentences do not clearly distinguish this skill from general productivity, PDF, or implementation-assistance requests. In an agent ecosystem, ambiguous routing increases unintended invocation, making behavior less predictable and potentially allowing this skill to intercept tasks better handled by safer or more specific skills.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.