Back to skill

Security audit

Work Productivity Nano Pdf Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper, but its activation language is too broad and may cause unwanted auto-selection.

Install only if you want a general Nano Pdf-style workflow helper, and consider tightening or disabling implicit invocation so ordinary PDF, editing, or bug-fix requests do not accidentally select this skill.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger examples are broad, generic, and closely resemble ordinary user requests, which can cause the skill to activate outside its intended scope. This increases the chance of unintended routing, response hijacking, or the skill being selected for unrelated PDF/workflow tasks where its instructions may override better-matched skills or confuse the agent.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger phrases are broad and generic enough to match ordinary requests about PDFs, editing, workflows, or bug fixing, which can cause the skill to activate outside its intended scope. In an agent ecosystem, this increases the risk of inappropriate routing, unexpected behavior, and accidental invocation of instructions or workflows the user did not explicitly request.

Vague Triggers

High
Confidence
96% confidence
Finding
The skill description is scoped to very common terms like 'pdf', 'edit', 'analysis', and 'implementation support', which can match a wide range of unrelated user requests and cause unintended activation. Over-broad routing increases the chance that this skill intercepts prompts outside its intended domain, leading to unsafe or incorrect handling and making downstream behavior harder to predict or control.

Vague Triggers

High
Confidence
98% confidence
Finding
The keyword list includes vague, high-frequency terms such as 'nano', 'pdf', 'edit', 'natural', 'language', and 'bug fix' without contextual constraints. These terms are likely to appear in many ordinary conversations, so the skill may be invoked spuriously, creating prompt-routing confusion and increasing the risk of inappropriate or lower-quality outputs.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The example trigger sentences are broad paraphrases of the marketing description and do not define what should or should not activate the skill. Without clear boundaries, implementers may treat these examples as permissive patterns, further widening activation scope and increasing accidental invocation in unrelated contexts.

Vague Triggers

High
Confidence
95% confidence
Finding
触发关键词包含过于通用的词,如“nano”“pdf”“edit”“natural”“language”“instructions”“bug fix”,与大量普通对话重叠,容易在并非该技能目标场景时被自动触发。这会导致错误路由、上下文污染,甚至让代理在不相关任务中套用该技能流程,降低安全边界与结果可靠性。

Vague Triggers

Medium
Confidence
87% confidence
Finding
技能描述中的适用条件较宽泛,如“需要围绕该需求获得实用流程、产物、检查清单、分析或实现支持时使用”,缺乏清晰边界,可能让调度器将许多泛化的生产力、编辑或实现类请求错误映射到此技能。虽然这更偏向路由与范围控制问题,但在代理系统中会放大误触发和越权式辅助的风险。

Vague Triggers

Medium
Confidence
91% confidence
Finding
The default prompt includes very broad trigger terms such as work-productivity, nano, and pdf, which can overlap with ordinary user language and cause the skill to activate in contexts the user did not clearly intend. This increases the risk of prompt-routing mistakes, unintended tool influence, and accidental exposure of the skill's behavior in unrelated conversations.

Vague Triggers

Medium
Confidence
94% confidence
Finding
Enabling implicit invocation without clear constraints allows the platform to auto-select this skill based on ambiguous language, which is especially risky when the skill description and prompt are already broad. In practice, this can lead to unintended invocation in unrelated tasks, creating prompt-injection surface and reducing user control over when the skill is applied.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger sentence begins with a very broad everyday phrase ('Help me'), which can cause the skill to activate in many unrelated conversations. Overbroad activation increases the chance of unintended invocation, context hijacking, or routing a user into this workflow when they did not request it, especially in multi-skill agent environments.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The phrase 'I need a practical workflow for ...' is generic and ambiguous enough to match many benign requests that are not specifically about Nano PDF-style workflows. In an agent system, such loose matching can cause accidental tool selection, data exposure to the wrong skill, or interference with the intended workflow.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.